nerdexam
(ISC)2

CCSP · Question #511

The SOC Type 2 reports are divided into five principles. Which of the five principles must also be included when auditing any of the other four principles?

The correct answer is C. Security. AICPA's SOC 2 framework is built on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security principle - which covers logical and physical access controls, risk management, and system monitoring - is considered…

Submitted by luis.pe· Apr 18, 2026Legal, Risk and Compliance

Question

The SOC Type 2 reports are divided into five principles. Which of the five principles must also be included when auditing any of the other four principles?

Options

  • AConfidentiality
  • BPrivacy
  • CSecurity
  • DAvailability

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    90% (27)

Explanation

AICPA's SOC 2 framework is built on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security principle - which covers logical and physical access controls, risk management, and system monitoring - is considered the foundational 'common criteria' that underpins all other principles. Because every other principle depends on the security controls being in place and functioning (you cannot have confidentiality without access controls, availability without security monitoring, etc.), the Security principle must always be included whenever any of the other four principles are being audited. It is the only mandatory principle; the other four are optional add-ons selected based on the organization's commitments.

Topics

#SOC 2#Trust Services Criteria#Compliance#Security Auditing

Community Discussion

No community discussion yet for this question.

Full CCSP Practice