CCSP · Question #489
Which type of controls are the SOC Type 1 reports specifically focused on?
The correct answer is C. Financial. SOC 1 (formerly SAS 70) reports are specifically focused on internal controls over financial reporting (ICFR). They are designed for service organizations whose services could impact a user entity's financial statements. This makes them relevant for auditors and financial…
Question
Which type of controls are the SOC Type 1 reports specifically focused on?
Options
- AIntegrity
- BPII
- CFinancial
- DPrivacy
How the community answered
(43 responses)- A5% (2)
- B5% (2)
- C88% (38)
- D2% (1)
Explanation
SOC 1 (formerly SAS 70) reports are specifically focused on internal controls over financial reporting (ICFR). They are designed for service organizations whose services could impact a user entity's financial statements. This makes them relevant for auditors and financial stakeholders. SOC 2 and SOC 3 reports, by contrast, focus on the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy)-not financial controls.
Topics
Community Discussion
No community discussion yet for this question.