ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingHard

A security manager is evaluating a new vendor's Software-as-a-Service (SaaS) solution. The vendor provides an attestation report that details the effectiveness of their security controls over a specific period, conducted by an independent third-party auditor. Which type of report is the security manager MOST likely reviewing?

  1. AISO 27001 Certification
  2. BVulnerability Assessment Report
  3. CSOC 2 Type II Report
  4. DPenetration Test Report
Show answer & explanation

Correct answer: C. SOC 2 Type II Report

A SOC 2 Type II report provides detailed information about the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy over a period of time. This aligns perfectly with an attestation report from an independent third-party auditor detailing control effectiveness for a SaaS vendor.

Why the other options are wrong

  • A. ISO 27001 certification indicates adherence to an Information Security Management System standard, but the report itself is an 'attestation report' and 'SOC 2 Type II' is a more specific and common form of such an attestation for SaaS vendors regarding control effectiveness.
  • B. A vulnerability assessment report lists identified vulnerabilities but doesn't attest to control effectiveness over time by an independent auditor.
  • D. A penetration test report details exploitation attempts and outcomes, not a general attestation of control effectiveness over time.

SOC 2 Type II Report

A report on Controls at a Service Organization relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy, covering the effectiveness of these controls over a specified period.

  • Issued by an independent auditor.
  • Provides assurance on the effectiveness of controls over time.
  • Commonly used for SaaS and cloud service providers.

Memory trick: THIRD-PARTY reports ASSURE TRUST, from SOC for services to ISO for systems.

More Security Assessment and Testing questions