ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy
An IS auditor is planning an audit of a new cloud-based enterprise resource planning (ERP) system. The organization has outsourced the ERP system's hosting and management to a third-party vendor. Which of the following documents is MOST critical for the auditor to review FIRST to understand the vendor's control environment?
- AThe service level agreement (SLA) with the cloud vendor.
- BThe organization's data privacy impact assessment (DPIA) for the ERP system.
- CThe vendor's System and Organization Controls (SOC) 2 report.
- DThe organization's internal cloud usage policy.
Show answer & explanationAnswer & explanation
Correct answer: C. The vendor's System and Organization Controls (SOC) 2 report.
A SOC 2 report provides an independent auditor's opinion on the design and operating effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy. This is crucial for understanding a third-party vendor's control environment.
Why the other options are wrong
- A. The SLA defines contractual obligations but does not detail the vendor's internal controls.
- B. The DPIA assesses privacy risks from the organization's perspective, not the vendor's control environment directly.
- D. While important for internal governance, it doesn't provide insight into the vendor's actual control environment.
SOC 2 Report
An independent audit report on a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.
- Provides assurance over third-party controls.
- Issued by an independent CPA firm.
- Crucial for evaluating outsourced services.
Memory trick: When auditing clouds, look for the 'SOC' of assurance.