nerdexam
(ISC)2

CCSP · Question #489

Which type of controls are the SOC Type 1 reports specifically focused on?

The correct answer is C. Financial. SOC 1 (formerly SAS 70) reports are specifically focused on internal controls over financial reporting (ICFR). They are designed for service organizations whose services could impact a user entity's financial statements. This makes them relevant for auditors and financial…

Submitted by haru.x· Apr 18, 2026Legal, Risk and Compliance

Question

Which type of controls are the SOC Type 1 reports specifically focused on?

Options

  • AIntegrity
  • BPII
  • CFinancial
  • DPrivacy

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    5% (2)
  • C
    88% (38)
  • D
    2% (1)

Explanation

SOC 1 (formerly SAS 70) reports are specifically focused on internal controls over financial reporting (ICFR). They are designed for service organizations whose services could impact a user entity's financial statements. This makes them relevant for auditors and financial stakeholders. SOC 2 and SOC 3 reports, by contrast, focus on the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy)-not financial controls.

Topics

#SOC reports#SOC 1#Financial reporting#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice