Soru

Zorluk: KolaySecurity Audits, Assessments, and Attestations

A cloud service provider needs to publish a high-level attestation document on its public website to demonstrate compliance with security best practices to prospective clients, without disclosing detailed control design or confidential testing procedures. Which report fulfills this requirement?

  1. SOC 3 reportCevap
  2. B
    SOC 2 Type II report
  3. C
    SOC 1 Type II report
  4. D
    SOC 2 Type I report

Cevap

A SOC 3 report provides a general-use, publicly shareable summary of security attestations without exposing confidential system design details.
A SOC 3 report is specifically created for general public distribution. It provides an executive summary of an organization's compliance with Trust Services Criteria without revealing sensitive details regarding system architecture or specific control testing results.

Adım Adım Çözüm

1
Identify the primary requirement in the scenario.
The organization requires a publicly accessible security attestation report that excludes sensitive internal architectural and testing details.
Prospective customers need proof of security posture, but public distribution of detailed audit reports poses a security risk.
2
Evaluate the scope and audience of available SOC reports.
SOC 1 and SOC 2 reports are restricted-use documents intended for management and existing clients, whereas SOC 3 reports are designated for public distribution.
SOC 3 provides an executive summary based on SOC 2 Trust Services Criteria without disclosing proprietary system details.

Anahtar Kavram

SOC 3 Public Attestation Reports
Bu soruyu puanla