CISSP · Question #1505
An application is used for funds transfer between an organization and a third-party. During a security audit, an issue with the business continuity/disaster recovery policy and procedures for this app
The correct answer is C. Service Organization Control (SOC) 2. Service Organization Control (SOC) 2 is a report that provides information about the security, availability, processing integrity, confidentiality, and privacy of a service organization's system. It is intended for users who need assurance about the controls at a service organiza
Question
An application is used for funds transfer between an organization and a third-party. During a security audit, an issue with the business continuity/disaster recovery policy and procedures for this application. Which of the following reports should the audit file with the organization?
Options
- AService Organization Control (SOC) 1
- BStatement on Auditing Standards (SAS) 70
- CService Organization Control (SOC) 2
- DStatement on Auditing Standards (SAS) 70-1
How the community answered
(19 responses)- A5% (1)
- B16% (3)
- C74% (14)
- D5% (1)
Explanation
Service Organization Control (SOC) 2 is a report that provides information about the security, availability, processing integrity, confidentiality, and privacy of a service organization's system. It is intended for users who need assurance about the controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A SOC 2 report can help an organization assess the business continuity/disaster recovery policy and procedures for an application that is outsourced to a third-party service provider.
Topics
Community Discussion
No community discussion yet for this question.