CCSP · Question #330
A cloud provider is looking to provide a higher level of assurance to current and potential cloud customers about the design and effectiveness of their security controls. Which of the following…
The correct answer is D. SOC 3. To provide a high level of assurance to potential cloud customers about the effectiveness of its security controls, a cloud provider would choose a SOC 3 audit report.
Question
A cloud provider is looking to provide a higher level of assurance to current and potential cloud customers about the design and effectiveness of their security controls. Which of the following audit reports would the cloud provider choose as the most appropriate to accomplish this goal? Response:
Options
- ASAS-70
- BSOC 1
- CSOC 2
- DSOC 3
How the community answered
(17 responses)- A6% (1)
- B6% (1)
- C18% (3)
- D71% (12)
Why each option
To provide a high level of assurance to potential cloud customers about the effectiveness of its security controls, a cloud provider would choose a SOC 3 audit report.
SAS-70 has been superseded by the SOC reports and is no longer the current standard for service organization control audits.
A SOC 1 report focuses on controls relevant to financial reporting, not primarily the security of a cloud provider's services.
A SOC 2 report provides a detailed analysis of controls over security and other trust principles but is a restricted-use report, typically shared only with existing customers under NDA.
A SOC 3 report is a general-use, publicly available report that provides a high-level summary of a service organization's internal controls related to security, availability, processing integrity, confidentiality, and privacy, making it suitable for broad distribution to potential customers seeking assurance.
Concept tested: Cloud provider audit reports (SOC)
Source: https://www.aicpa.org/resources/toolkit/soc-suite-of-services
Topics
Community Discussion
No community discussion yet for this question.