CompTIA Security+ (SY0-701)Security Program Management and OversightHard

A SaaS provider's enterprise customers require independent assurance regarding the design and operating effectiveness of the provider's security controls over a six-month period, without the report being made publicly available. Which type of report should the provider obtain?

  1. APCI DSS Attestation of Compliance
  2. BISO 27001 certification
  3. CSOC 2 Type II
  4. DSOC 1 Type II
Show answer & explanation

Correct answer: C. SOC 2 Type II

A SOC 2 Type II report evaluates the design and operating effectiveness of controls related to security, availability, confidentiality, and other Trust Services Criteria over a period of time, and is typically shared confidentially with customers rather than published publicly.

Why the other options are wrong

  • A. A PCI AoC addresses payment card compliance specifically, not general security controls.
  • B. ISO 27001 is a certification against an ISMS standard, not a period-based control effectiveness report.
  • D. SOC 1 focuses on controls relevant to financial reporting, not general security operations.

SOC 2 Type II Report

An independent audit report evaluating the design and operating effectiveness of a service organization's security controls over a specified period, typically shared privately with customers.

  • SOC 1 = financial reporting controls
  • SOC 2 Type I = design only, at a point in time
  • SOC 2 Type II = design AND operating effectiveness over time

Memory trick: SOC 2 Type Two Tests Time, Not Just a Snapshot

More Security Program Management and Oversight questions