CCSP · Question #127
What principle must always been included with an SOC 2 report?
The correct answer is B. Security. An SOC 2 report always includes the "Security" principle, which is considered the baseline and mandatory common criteria across all SOC 2 reports.
Question
What principle must always been included with an SOC 2 report?
Options
- AConfidentiality
- BSecurity
- CPrivacy
- DProcessing integrity
How the community answered
(26 responses)- B92% (24)
- C4% (1)
- D4% (1)
Why each option
An SOC 2 report always includes the "Security" principle, which is considered the baseline and mandatory common criteria across all SOC 2 reports.
Confidentiality is an optional Trust Services Criterion that can be included in an SOC 2 report, depending on the services provided and the client's needs.
The American Institute of Certified Public Accountants (AICPA) defines five Trust Services Criteria for SOC 2 reports: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Of these, "Security" is the only mandatory common criteria that must be included in every SOC 2 report, serving as the baseline for protecting information.
Privacy is an optional Trust Services Criterion that can be included in an SOC 2 report, depending on the services provided and the client's needs.
Processing integrity is an optional Trust Services Criterion that can be included in an SOC 2 report, depending on the services provided and the client's needs.
Concept tested: SOC 2 Trust Services Criteria
Source: https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/aicpa-soc-2-report
Topics
Community Discussion
No community discussion yet for this question.