A security analyst at a financial institution is conducting a vendor risk assessment for a prospective software-as-a-service (SaaS) human resources platform. The vendor provides a SOC 1 Type II report to demonstrate financial reporting integrity. However, the analyst must verify the operational effectiveness of the vendor's data encryption, system availability, and confidentiality controls over the past 12 months. Which attestation deliverable should the analyst request from the vendor?
- SOC 2 Type II reportCevap
- BSOC 1 Type I report
- CSOC 2 Type I report
- DSOC 3 report
Cevap
The analyst should request a SOC 2 Type II report.
A SOC 2 Type II report assesses a service organization's controls based on the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and verifies their operational effectiveness over a sustained period of time (typically 6 to 12 months).
Adım Adım Çözüm
Anahtar Kavram
SOC 2 Type II Attestation Reports