Soru

Zorluk: ZorSecurity Audits, Assessments, and Attestations

A healthcare enterprise is reviewing security documentation from a third-party Cloud Software as a Service (SaaS) vendor that stores Protected Health Information (PHI). The enterprise's compliance framework requires independent third-party verification that the vendor's Security, Confidentiality, and Availability controls were appropriately designed and operated effectively throughout a continuous nine-month observation period. Which of the following independent attestations best satisfies this requirement?

  1. A SOC 2 Type II reportCevap
  2. B
    A SOC 2 Type I report
  3. C
    A SOC 1 Type II report
  4. D
    A SOC 3 report

Cevap

A SOC 2 Type II report best satisfies the requirement because it evaluates both control design and operational effectiveness over a continuous observation period for Trust Services Criteria.
A SOC 2 Type II report specifically measures the suitability of design and the operational effectiveness of controls related to the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy) over a specified period of time. Because the enterprise requires proof of effective operation over a continuous nine-month window, a SOC 2 Type II report is the exact matching attestation standard.

Adım Adım Çözüm

1
Analyze the scope requirement
The requirement demands evaluation of Security, Confidentiality, and Availability controls, matching the AICPA Trust Services Criteria (SOC 2 or SOC 3 domain, not financial reporting/SOC 1).
SOC 1 focuses exclusively on controls relevant to financial reporting (ICFR), whereas SOC 2 covers Trust Services Criteria.
2
Evaluate the timeframe requirement
The requirement specifies testing over a continuous nine-month observation period, which requires a Type II evaluation.
Type I reports only assess control design at a single specific date, whereas Type II reports assess operational effectiveness over a period of time.
3
Determine the necessary depth of report detail
The compliance review requires thorough auditor testing evidence rather than a general public disclosure statement.
A SOC 2 Type II report provides detailed testing procedures and auditor findings, unlike a high-level public SOC 3 report.

Anahtar Kavram

SOC 2 Type II vs. Type I and SOC 1 Attestation Scope
Tahmini Süre:1m 30s
Bu soruyu puanla