CCSP · Question #111
Which type of report is considered for "general" use and does not contain any sensitive information?
The correct answer is C. SOC 3. SOC 3 reports are intended for general public consumption as they provide a high-level summary of internal controls related to security, availability, processing integrity, confidentiality, and privacy without revealing sensitive details.
Question
Which type of report is considered for "general" use and does not contain any sensitive information?
Options
- ASOC 1
- BSAS-70
- CSOC 3
- DSOC 2
How the community answered
(31 responses)- B3% (1)
- C90% (28)
- D6% (2)
Why each option
SOC 3 reports are intended for general public consumption as they provide a high-level summary of internal controls related to security, availability, processing integrity, confidentiality, and privacy without revealing sensitive details.
SOC 1 reports focus on internal controls over financial reporting and are restricted to users who need to understand those controls.
SAS 70 was an auditing standard that has been replaced by the SOC reporting framework.
SOC 3 reports are designed for general use, offering a public summary of an organization's internal controls over security, availability, processing integrity, confidentiality, and privacy. Unlike SOC 1 or SOC 2 reports, they do not contain sensitive or proprietary information, making them suitable for broader distribution to potential customers or the public.
SOC 2 reports provide a detailed assurance report on controls related to security, availability, processing integrity, confidentiality, and privacy, but they contain sensitive information and are restricted to specific stakeholders.
Concept tested: SOC report types and audiences
Source: https://www.aicpa-cima.com/resources/download/soc-reports-overview
Topics
Community Discussion
No community discussion yet for this question.