nerdexam
(ISC)2

CCSP · Question #127

What principle must always been included with an SOC 2 report?

The correct answer is B. Security. An SOC 2 report always includes the "Security" principle, which is considered the baseline and mandatory common criteria across all SOC 2 reports.

Submitted by jakub_pl· Apr 18, 2026Legal, Risk and Compliance

Question

What principle must always been included with an SOC 2 report?

Options

  • AConfidentiality
  • BSecurity
  • CPrivacy
  • DProcessing integrity

How the community answered

(26 responses)
  • B
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Why each option

An SOC 2 report always includes the "Security" principle, which is considered the baseline and mandatory common criteria across all SOC 2 reports.

AConfidentiality

Confidentiality is an optional Trust Services Criterion that can be included in an SOC 2 report, depending on the services provided and the client's needs.

BSecurityCorrect

The American Institute of Certified Public Accountants (AICPA) defines five Trust Services Criteria for SOC 2 reports: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Of these, "Security" is the only mandatory common criteria that must be included in every SOC 2 report, serving as the baseline for protecting information.

CPrivacy

Privacy is an optional Trust Services Criterion that can be included in an SOC 2 report, depending on the services provided and the client's needs.

DProcessing integrity

Processing integrity is an optional Trust Services Criterion that can be included in an SOC 2 report, depending on the services provided and the client's needs.

Concept tested: SOC 2 Trust Services Criteria

Source: https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/aicpa-soc-2-report

Topics

#SOC 2#Trust Service Criteria#Security#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice