A multinational financial enterprise is undergoing a comprehensive regulatory oversight review following a cloud migration. The Chief Risk Officer must provide formal verification to federal regulators that administrative access controls and data encryption mechanisms within the multi-tenant software-as-a-service environment were continuously evaluated for operational effectiveness across the entire preceding 12-month fiscal period. Which of the following independent attestations or evaluation mechanisms fulfills this regulatory requirement?
- A SOC 2 Type II report covering the operating effectiveness of Trust Services Criteria controls over the 12-month periodCevap
- BA SOC 2 Type I report validating the design suitability and baseline implementation of security controls at the date of migration
- CA SOC 3 attestation report outlining high-level security management practices for public disclosure
- DAn external network penetration testing and technical vulnerability assessment report executed at the end of the fiscal year
Cevap
The correct evaluation mechanism is a SOC 2 Type II report covering the operating effectiveness of Trust Services Criteria controls over the 12-month period.
A SOC 2 Type II report provides an independent third-party attestation that evaluates both the suitability of control design and the operational effectiveness of security controls based on the AICPA Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) over a specified period (typically 6 to 12 months). This meets the regulatory demand for proof of continuous operational effectiveness across the preceding fiscal year.
Adım Adım Çözüm
Anahtar Kavram
SOC Report Types and Attestation Scopes (Type I vs Type II)
Tahmini Süre:3m 0s