A logistics firm plans to contract a third-party software vendor to manage its real-time route optimization platform. Prior to completing vendor onboarding, the security manager requires verifiable proof that the vendor's security controls have operated effectively throughout a sustained six-month evaluation period. Which of the following third-party documentation types best fulfills this requirement?
- SOC 2 Type II reportCevap
- BSOC 2 Type I report
- CVendor Security Assessment Questionnaire (VSAQ)
- DService Level Agreement (SLA) performance log
Cevap
SOC 2 Type II report
A System and Organization Controls (SOC) 2 Type II report provides independent third-party auditor verification regarding both the design and operational effectiveness of security controls over a designated testing period (typically 6 to 12 months). This directly aligns with the requirement for proof of sustained control operating performance.
Adım Adım Çözüm
Anahtar Kavram
Third-Party Risk Assessment Artifacts and SOC Reporting