nerdexam
(ISC)2

CISSP · Question #1505

An application is used for funds transfer between an organization and a third-party. During a security audit, an issue with the business continuity/disaster recovery policy and procedures for this app

The correct answer is C. Service Organization Control (SOC) 2. Service Organization Control (SOC) 2 is a report that provides information about the security, availability, processing integrity, confidentiality, and privacy of a service organization's system. It is intended for users who need assurance about the controls at a service organiza

Submitted by olafpl· Mar 5, 2026Security Assessment and Testing

Question

An application is used for funds transfer between an organization and a third-party. During a security audit, an issue with the business continuity/disaster recovery policy and procedures for this application. Which of the following reports should the audit file with the organization?

Options

  • AService Organization Control (SOC) 1
  • BStatement on Auditing Standards (SAS) 70
  • CService Organization Control (SOC) 2
  • DStatement on Auditing Standards (SAS) 70-1

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    16% (3)
  • C
    74% (14)
  • D
    5% (1)

Explanation

Service Organization Control (SOC) 2 is a report that provides information about the security, availability, processing integrity, confidentiality, and privacy of a service organization's system. It is intended for users who need assurance about the controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A SOC 2 report can help an organization assess the business continuity/disaster recovery policy and procedures for an application that is outsourced to a third-party service provider.

Topics

#SOC reports#third-party risk#audit reports#BC/DR

Community Discussion

No community discussion yet for this question.

Full CISSP Practice