nerdexam
(ISC)2

CISSP · Question #1507

Which reporting type requires a service organization to describe its system and define its control objectives and controls that are relevant to users internal control over financial reporting?

The correct answer is B. Service Organization Control 1 (SOC1). Service Organization Control 1 (SOC1) is a report that provides information about the controls at a service organization that may affect the user entities' internal control over financial reporting. It is intended for users who have a reasonable understanding of the nature and si

Submitted by devops_kid· Mar 5, 2026Security Assessment and Testing

Question

Which reporting type requires a service organization to describe its system and define its control objectives and controls that are relevant to users internal control over financial reporting?

Options

  • AStatement on Auditing Standards (SAS)70
  • BService Organization Control 1 (SOC1)
  • CService Organization Control 2 (SOC2)
  • DService Organization Control 3 (SOC3)

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    94% (17)

Explanation

Service Organization Control 1 (SOC1) is a report that provides information about the controls at a service organization that may affect the user entities' internal control over financial reporting. It is intended for users who have a reasonable understanding of the nature and significance of the service provided, the service organization's system, and the applicable trust services criteria. A SOC 1 report can help an organization evaluate the effectiveness of the service organization's controls that are relevant to users internal control over financial reporting.

Topics

#SOC reports#financial reporting#auditing standards

Community Discussion

No community discussion yet for this question.

Full CISSP Practice