CompTIA Security+ (SY0-701)Security Program Management and OversightHard
A SaaS provider's enterprise customers require independent assurance regarding the design and operating effectiveness of the provider's security controls over a six-month period, without the report being made publicly available. Which type of report should the provider obtain?
- APCI DSS Attestation of Compliance
- BISO 27001 certification
- CSOC 2 Type II
- DSOC 1 Type II
Show answer & explanationAnswer & explanation
Correct answer: C. SOC 2 Type II
A SOC 2 Type II report evaluates the design and operating effectiveness of controls related to security, availability, confidentiality, and other Trust Services Criteria over a period of time, and is typically shared confidentially with customers rather than published publicly.
Why the other options are wrong
- A. A PCI AoC addresses payment card compliance specifically, not general security controls.
- B. ISO 27001 is a certification against an ISMS standard, not a period-based control effectiveness report.
- D. SOC 1 focuses on controls relevant to financial reporting, not general security operations.
SOC 2 Type II Report
An independent audit report evaluating the design and operating effectiveness of a service organization's security controls over a specified period, typically shared privately with customers.
- SOC 1 = financial reporting controls
- SOC 2 Type I = design only, at a point in time
- SOC 2 Type II = design AND operating effectiveness over time
Memory trick: SOC 2 Type Two Tests Time, Not Just a Snapshot