CISSP · Question #875
Which of the following reports provides the BEST attestation of detailed controls when evaluating an Identity as a Service (IDaaS) solution?
The correct answer is B. Service Organization Control (SOC) 2. When evaluating an Identity as a Service (IDaaS) solution, a Service Organization Control (SOC) 2 report offers the most comprehensive attestation of detailed controls related to security and operational aspects.
Question
Which of the following reports provides the BEST attestation of detailed controls when evaluating an Identity as a Service (IDaaS) solution?
Options
- AService Organization Control (SOC) 1
- BService Organization Control (SOC) 2
- CService Organization Control (SOC) 3
- DStatement on Auditing Standards (SAS) 70
How the community answered
(29 responses)- A7% (2)
- B72% (21)
- C17% (5)
- D3% (1)
Why each option
When evaluating an Identity as a Service (IDaaS) solution, a Service Organization Control (SOC) 2 report offers the most comprehensive attestation of detailed controls related to security and operational aspects.
SOC 1 reports primarily focus on controls relevant to a user entity's internal control over financial reporting, not the detailed security and operational controls of an IDaaS solution.
A SOC 2 report specifically addresses controls related to security, availability, processing integrity, confidentiality, and privacy, which are critical Trust Services Criteria for an IDaaS solution. It provides detailed information on the service organization's system and the suitability of the design and operating effectiveness of controls, making it ideal for evaluating an IDaaS provider.
SOC 3 reports are general-use reports that provide a high-level overview without the detailed control information necessary for a thorough technical evaluation of an IDaaS solution.
SAS 70 is an outdated auditing standard that has been replaced by the SOC reporting framework and focused on internal controls over financial reporting, not the broader operational controls of an IDaaS.
Concept tested: Evaluating IDaaS controls using audit reports (SOC 2)
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-1-2-3
Topics
Community Discussion
No community discussion yet for this question.