ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy

An IS auditor is planning an audit of a new cloud-based enterprise resource planning (ERP) system. The organization has outsourced the ERP system's hosting and management to a third-party vendor. Which of the following documents is MOST critical for the auditor to review FIRST to understand the vendor's control environment?

  1. AThe service level agreement (SLA) with the cloud vendor.
  2. BThe organization's data privacy impact assessment (DPIA) for the ERP system.
  3. CThe vendor's System and Organization Controls (SOC) 2 report.
  4. DThe organization's internal cloud usage policy.
Show answer & explanation

Correct answer: C. The vendor's System and Organization Controls (SOC) 2 report.

A SOC 2 report provides an independent auditor's opinion on the design and operating effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy. This is crucial for understanding a third-party vendor's control environment.

Why the other options are wrong

  • A. The SLA defines contractual obligations but does not detail the vendor's internal controls.
  • B. The DPIA assesses privacy risks from the organization's perspective, not the vendor's control environment directly.
  • D. While important for internal governance, it doesn't provide insight into the vendor's actual control environment.

SOC 2 Report

An independent audit report on a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.

  • Provides assurance over third-party controls.
  • Issued by an independent CPA firm.
  • Crucial for evaluating outsourced services.

Memory trick: When auditing clouds, look for the 'SOC' of assurance.

More Domain 1: Information System Auditing Process questions