A fintech enterprise developing a cloud-native payment gateway is undergoing a third-party risk assessment by a prospective banking partner. The partner demands verified proof that security, confidentiality, and availability controls were not only properly designed but also maintained operational effectiveness throughout the preceding nine months. Which attestation report should the fintech enterprise provide to satisfy this requirement?
- SOC 2 Type II reportCevap
- BSOC 2 Type I report
- CSOC 1 Type II report
- DSOC 3 report
Cevap
SOC 2 Type II report
A SOC 2 Type II report evaluates whether specified controls were designed appropriately and operated effectively over an extended period (typically 6 to 12 months) based on the AICPA Trust Services Criteria (security, availability, confidentiality, processing integrity, and privacy).
Adım Adım Çözüm
Anahtar Kavram
SOC Report Types and Attestation Scopes