nerdexam
(ISC)2

CISSP · Question #1259

An organization is planning to have an it audit of its as a Service (SaaS) application to demonstrate to external parties that the security controls around availability are designed. The audit report

The correct answer is D. SOC 2 Type 2. A SOC 2 Type 2 report would best fit the needs of the organization that wants to have an IT audit of its SaaS application to demonstrate the security controls around availability. A SOC 2 Type 2 report provides information about the design and the operating effectiveness of the c

Submitted by layla.eg· Mar 5, 2026Security Assessment and Testing

Question

An organization is planning to have an it audit of its as a Service (SaaS) application to demonstrate to external parties that the security controls around availability are designed. The audit report must also cover a certain period of time to show the operational effectiveness of the controls. Which Service Organization Control (SOC) report would BEST fit their needs?

Options

  • ASOC 1 Type 1
  • BSOC 1 Type 2
  • CSOC 2 Type 1
  • DSOC 2 Type 2

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    3% (1)
  • C
    8% (3)
  • D
    78% (31)

Explanation

A SOC 2 Type 2 report would best fit the needs of the organization that wants to have an IT audit of its SaaS application to demonstrate the security controls around availability. A SOC 2 Type 2 report provides information about the design and the operating effectiveness of the controls at a service organization relevant to the availability trust service category, as well as the other trust service categories such as security, processing integrity, confidentiality, and privacy. A SOC 2 Type 2 report covers a specified period of time, usually between six and twelve months, and includes the description of the tests of controls and the results performed by the auditor. A SOC 2 Type 2 report is intended for the general or the restricted use of the user entities and the other interested parties that need to understand the security controls of the service organization.

Topics

#SOC reports#SaaS security#audit types#operational effectiveness

Community Discussion

No community discussion yet for this question.

Full CISSP Practice