A global logistics organization is evaluating a cloud-based warehouse management platform to manage critical supply chain operations. The security team requires verification that the vendor's security controls addressing system availability and data confidentiality are not only properly designed, but have also been evaluated for operational effectiveness over a six-month monitoring window. Which of the following audit reports or attestations should the organization request from the vendor?
- A SOC 2 Type II reportCevap
- BA SOC 2 Type I report
- CA SOC 1 Type II report
- DA SOC 3 report
Cevap
A SOC 2 Type II report
A SOC 2 Type II report specifically evaluates the design and operating effectiveness of security controls categorized under the Trust Services Criteria (such as availability, confidentiality, and security) over a defined period (such as six months).
Adım Adım Çözüm
Anahtar Kavram
SOC Report Types and Attestation Scopes