A software-as-a-service (SaaS) provider is required to achieve SOC 2 Type 2 certification, which necessitates strong controls over data security, availability, processing integrity, confidentiality, and privacy. The cybersecurity architect is evaluating security operations strategies. Which strategy best supports continuous evidence collection and reporting for SOC 2 Type 2 compliance?
- APerforming quarterly manual audits of system configurations and access logs.
- BRelying on developers to self-attest to secure coding practices and change management processes.
- CImplementing a Governance, Risk, and Compliance (GRC) platform integrated with cloud security posture management (CSPM) and security information and event management (SIEM) for automated control monitoring, evidence collection, and reporting.
- DFocusing solely on external penetration testing to identify vulnerabilities before the audit.
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing a Governance, Risk, and Compliance (GRC) platform integrated with cloud security posture management (CSPM) and security information and event management (SIEM) for automated control monitoring, evidence collection, and reporting.
An integrated GRC platform with CSPM and SIEM provides automated, continuous monitoring of security controls, real-time evidence collection, and streamlined reporting, which is essential for demonstrating continuous compliance required for SOC 2 Type 2 certification.
Why the other options are wrong
- A. Quarterly manual audits are insufficient for continuous monitoring and evidence collection required for SOC 2 Type 2, leading to compliance gaps and increased audit effort.
- B. Self-attestation lacks the objective evidence and verification required for SOC 2 Type 2 certification.
- D. While penetration testing is important, it's a point-in-time assessment and does not provide continuous evidence of operational control effectiveness over time, which is critical for SOC 2 Type 2.
GRC Platform
A software solution that integrates and manages an organization's governance, risk management, and compliance activities, providing a unified view of risk and control status.
- Automates compliance monitoring and evidence collection.
- Streamlines audit processes and reporting.
- Provides visibility into risk posture and control effectiveness.
Memory trick: GRC Platform Automates SOC 2 Proof