CCSP · Question #29
You are performing an audit of the security controls used in a cloud environment. Which of the following would best serve your purpose?
The correct answer is D. A SOC 3 report from another (external) auditor. When auditing security controls in a cloud environment, a SOC 3 report provides an external auditor's opinion on the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.
Question
You are performing an audit of the security controls used in a cloud environment. Which of the following would best serve your purpose?
Options
- AThe business impact analysis (BIA)
- BA copy of the VM baseline configuration
- CThe latest version of the company's financial records
- DA SOC 3 report from another (external) auditor
How the community answered
(18 responses)- A11% (2)
- C6% (1)
- D83% (15)
Why each option
When auditing security controls in a cloud environment, a SOC 3 report provides an external auditor's opinion on the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.
A business impact analysis (BIA) assesses the potential effects of an interruption to critical business functions, not the effectiveness of security controls in a cloud environment.
A VM baseline configuration shows how a *single VM* is configured, but doesn't provide an overall assessment of the broader security controls and processes implemented across the entire cloud environment by the provider.
The latest version of the company's financial records is irrelevant for an audit of security controls in a cloud environment.
A SOC 3 report, provided by an external auditor, offers a publicly available summary of a cloud service provider's internal controls relevant to security, availability, processing integrity, confidentiality, and privacy. For an organization auditing security controls in a cloud environment, reviewing this report allows them to gain assurance about the cloud provider's control effectiveness without conducting their own exhaustive audit of the provider's infrastructure.
Concept tested: Cloud security auditing & SOC reports
Source: https://www.aicpa.org/resources/download/understanding-the-difference-between-a-soc-1-soc-2-and-soc-3-report
Topics
Community Discussion
No community discussion yet for this question.