A healthcare technology company hosts its multi-tenant application on a cloud service provider's infrastructure. To satisfy client enterprise compliance requirements, the company must provide an independent auditor's report verifying that its security controls protecting customer data were appropriately designed and operated effectively throughout the preceding 12-month period. Which of the following compliance deliverables best satisfies this requirement?
- SOC 2 Type II reportCevap
- BSOC 2 Type I report
- CSOC 1 Type II report
- DVulnerability assessment report
Cevap
SOC 2 Type II report
A SOC 2 Type II report provides independent attestation that an organization's security controls are properly designed and operated effectively over a defined evaluation timeframe (such as 6 to 12 months). This fulfills both the scope (security/confidentiality) and operational duration requirements.
Adım Adım Çözüm
Anahtar Kavram
SOC 2 Type II Attestation Reports
Tahmini Süre:1m 15s