CCSP · Question #511
The SOC Type 2 reports are divided into five principles. Which of the five principles must also be included when auditing any of the other four principles?
The correct answer is C. Security. AICPA's SOC 2 framework is built on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security principle - which covers logical and physical access controls, risk management, and system monitoring - is considered…
Question
The SOC Type 2 reports are divided into five principles. Which of the five principles must also be included when auditing any of the other four principles?
Options
- AConfidentiality
- BPrivacy
- CSecurity
- DAvailability
How the community answered
(30 responses)- A7% (2)
- B3% (1)
- C90% (27)
Explanation
AICPA's SOC 2 framework is built on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security principle - which covers logical and physical access controls, risk management, and system monitoring - is considered the foundational 'common criteria' that underpins all other principles. Because every other principle depends on the security controls being in place and functioning (you cannot have confidentiality without access controls, availability without security monitoring, etc.), the Security principle must always be included whenever any of the other four principles are being audited. It is the only mandatory principle; the other four are optional add-ons selected based on the organization's commitments.
Topics
Community Discussion
No community discussion yet for this question.