Soru

Zorluk: OrtaSecurity Audits, Assessments, and Attestations

A healthcare technology company hosts its multi-tenant application on a cloud service provider's infrastructure. To satisfy client enterprise compliance requirements, the company must provide an independent auditor's report verifying that its security controls protecting customer data were appropriately designed and operated effectively throughout the preceding 12-month period. Which of the following compliance deliverables best satisfies this requirement?

  1. SOC 2 Type II reportCevap
  2. B
    SOC 2 Type I report
  3. C
    SOC 1 Type II report
  4. D
    Vulnerability assessment report

Cevap

SOC 2 Type II report
A SOC 2 Type II report provides independent attestation that an organization's security controls are properly designed and operated effectively over a defined evaluation timeframe (such as 6 to 12 months). This fulfills both the scope (security/confidentiality) and operational duration requirements.

Adım Adım Çözüm

1
Determine the subject area required for the compliance report.
The requirement calls for evaluating data protection and security controls, pointing toward a SOC 2 audit focusing on Trust Services Criteria (Security, Confidentiality) rather than financial reporting controls evaluated under SOC 1.
SOC 2 reports specifically cover security, availability, processing integrity, confidentiality, and privacy controls.
2
Evaluate the timeframe requirement specified in the scenario.
The client requires proof of operational effectiveness over a continuous 12-month period.
Type II reports test and verify operational effectiveness across a defined monitoring period (e.g., 6 to 12 months), whereas Type I reports only verify control design at a single point in time.

Anahtar Kavram

SOC 2 Type II Attestation Reports
Tahmini Süre:1m 15s
Bu soruyu puanla