ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingHard
A security manager is evaluating a new vendor's Software-as-a-Service (SaaS) solution. The vendor provides an attestation report that details the effectiveness of their security controls over a specific period, conducted by an independent third-party auditor. Which type of report is the security manager MOST likely reviewing?
- AISO 27001 Certification
- BVulnerability Assessment Report
- CSOC 2 Type II Report
- DPenetration Test Report
Show answer & explanationAnswer & explanation
Correct answer: C. SOC 2 Type II Report
A SOC 2 Type II report provides detailed information about the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy over a period of time. This aligns perfectly with an attestation report from an independent third-party auditor detailing control effectiveness for a SaaS vendor.
Why the other options are wrong
- A. ISO 27001 certification indicates adherence to an Information Security Management System standard, but the report itself is an 'attestation report' and 'SOC 2 Type II' is a more specific and common form of such an attestation for SaaS vendors regarding control effectiveness.
- B. A vulnerability assessment report lists identified vulnerabilities but doesn't attest to control effectiveness over time by an independent auditor.
- D. A penetration test report details exploitation attempts and outcomes, not a general attestation of control effectiveness over time.
SOC 2 Type II Report
A report on Controls at a Service Organization relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy, covering the effectiveness of these controls over a specified period.
- Issued by an independent auditor.
- Provides assurance on the effectiveness of controls over time.
- Commonly used for SaaS and cloud service providers.
Memory trick: THIRD-PARTY reports ASSURE TRUST, from SOC for services to ISO for systems.