(ISC)2
CCSP · Question #815
Which kind of SSAE audit reviews controls dealing with the organization's controls for assuring the confidentiality, integrity, and availability of data?
The correct answer is B. SOC 2. SOC 2 deals with the CIA triad. SOC 1 is for financial reporting. SOC 3 is only an attestation by the auditor. There is no SOC 4.
Submitted by weili_xi· Apr 18, 2026Legal, Risk and Compliance
Question
Which kind of SSAE audit reviews controls dealing with the organization's controls for assuring the confidentiality, integrity, and availability of data?
Options
- ASOC 1
- BSOC 2
- CSOC 3
- DSOC 4
How the community answered
(42 responses)- A7% (3)
- B88% (37)
- C2% (1)
- D2% (1)
Explanation
SOC 2 deals with the CIA triad. SOC 1 is for financial reporting. SOC 3 is only an attestation by the auditor. There is no SOC 4.
Topics
#SOC Reports#Audit and Assurance#Compliance#CIA Triad
Community Discussion
No community discussion yet for this question.