CCAK · Question #103
Your company is purchasing an application from a vendor. They do not allow you to perform an on-site audit on their information system. However, they say, they will provide the third-party audit…
The correct answer is B. SOC 2, TYPE 2. A SOC 2, Type 2 report is the industry-standard third-party attestation report provided by cloud vendors and SaaS providers to customers who cannot perform on-site audits. SOC 2 reports assess controls relevant to security, availability, processing integrity, confidentiality…
Question
Your company is purchasing an application from a vendor. They do not allow you to perform an on-site audit on their information system. However, they say, they will provide the third-party audit attestation on the adequate control design within their environment. Which report is the vendor providing you?
Options
- ASOC 3
- BSOC 2, TYPE 2
- CSOC 1
- DSOC 2, TYPE 1
How the community answered
(30 responses)- A13% (4)
- B77% (23)
- C7% (2)
- D3% (1)
Explanation
A SOC 2, Type 2 report is the industry-standard third-party attestation report provided by cloud vendors and SaaS providers to customers who cannot perform on-site audits. SOC 2 reports assess controls relevant to security, availability, processing integrity, confidentiality, and privacy (Trust Services Criteria). A Type 2 report covers both the design and the operating effectiveness of controls over a defined period (typically 6–12 months), making it far more valuable than Type 1 (design only). SOC 1 (C) addresses financial reporting controls, SOC 3 (A) is a public-facing summary without detailed findings, and SOC 2 Type 1 (D) only covers design at a point in time.
Topics
Community Discussion
No community discussion yet for this question.