nerdexam
(ISC)2

CCSP · Question #84

What are SOCI/SOCII/SOCIII?

The correct answer is C. Audit reports. SOC (System and Organization Controls) reports are a suite of audit reports that evaluate a service organization's internal controls.

Submitted by wei.xz· Apr 18, 2026Legal, Risk and Compliance

Question

What are SOCI/SOCII/SOCIII?

Options

  • ARisk management frameworks
  • BAccess controls
  • CAudit reports
  • DSoftware development phases

How the community answered

(30 responses)
  • A
    3% (1)
  • C
    93% (28)
  • D
    3% (1)

Why each option

SOC (System and Organization Controls) reports are a suite of audit reports that evaluate a service organization's internal controls.

ARisk management frameworks

Risk management frameworks provide a structured approach to managing risk, whereas SOC reports are the outcome of an audit against specific control objectives, not a framework itself.

BAccess controls

Access controls are mechanisms used to regulate who or what can view or use resources, which might be audited within a SOC report, but SOC reports themselves are not access controls.

CAudit reportsCorrect

SOC reports (SOC 1, SOC 2, and SOC 3) are independent audit reports issued by a CPA firm that assess the effectiveness of a service organization's controls over information systems that affect its customers. They provide assurance regarding the security, availability, processing integrity, confidentiality, and privacy of the data processed by the service organization.

DSoftware development phases

Software development phases describe stages in the software lifecycle, which is unrelated to the purpose of SOC reports.

Concept tested: SOC report types and purpose

Source: https://www.aicpa.org/news/aicpanews/2011/service-organization-controls-soc-reports-for-service-organizations.html

Topics

#SOC reports#Auditing#Compliance#Third-party assessment

Community Discussion

No community discussion yet for this question.

Full CCSP Practice