An enterprise security manager is evaluating a third-party cloud service provider and requires an independent audit report that verifies the operational effectiveness of the provider's security controls over a six-month testing period. Which of the following attestation reports should the security manager request?
- SOC 2 Type II reportCevap
- BSOC 2 Type I report
- CSOC 1 Type II report
- DVulnerability assessment report
Cevap
SOC 2 Type II report
The SOC 2 Type II report is specifically designed to provide an independent audit of a service organization's security controls, evaluating both the design suitability and operational effectiveness over a specified testing period (typically 6 to 12 months).
Adım Adım Çözüm
Anahtar Kavram
SOC 2 Type II reports provide third-party attestation of the operational effectiveness of security controls over a specified time period.