CCSP · Question #817
Which kind of SSAE audit report is most beneficial for a cloud customer, even though it's unlikely the cloud provider will share it?
The correct answer is C. SOC 2 Type 2. SOC 2 Type 2 evaluates a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy over an extended period of time (typically 6–12 months), demonstrating operational effectiveness rather than just design. This makes it f
Question
Which kind of SSAE audit report is most beneficial for a cloud customer, even though it's unlikely the cloud provider will share it?
Options
- ASOC 3
- BSOC 1 Type 2
- CSOC 2 Type 2
- DSOC 1 Type 1
How the community answered
(29 responses)- A3% (1)
- C93% (27)
- D3% (1)
Explanation
SOC 2 Type 2 evaluates a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy over an extended period of time (typically 6–12 months), demonstrating operational effectiveness rather than just design. This makes it far more valuable to cloud customers than a Type 1 (point-in-time snapshot) or SOC 1 (focused on financial reporting controls). SOC 3 is a sanitized public summary with far less detail. Providers are reluctant to share SOC 2 Type 2 because it contains detailed, sensitive information about their internal security architecture and any identified exceptions.
Topics
Community Discussion
No community discussion yet for this question.