ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy

An IS auditor is conducting an audit of an organization's cloud service provider. The organization relies on the cloud provider for critical infrastructure and data processing. To obtain assurance over the effectiveness of controls at the service organization, which of the following reports would be MOST appropriate for the IS auditor to request?

  1. AA standard contractual agreement between the organization and the cloud provider.
  2. BA Service Organization Control (SOC) 2 Type 2 report.
  3. CA general financial audit report from the cloud provider.
  4. DThe cloud provider's internal risk assessment documentation.
Show answer & explanation

Correct answer: B. A Service Organization Control (SOC) 2 Type 2 report.

A SOC 2 Type 2 report specifically addresses the design and operating effectiveness of controls at a service organization related to security, availability, processing integrity, confidentiality, or privacy, making it the most relevant for an IS auditor.

Why the other options are wrong

  • A. A contractual agreement outlines terms and conditions but does not provide evidence of the operating effectiveness of controls.
  • C. A general financial audit report focuses on financial statements, not the IT controls relevant to the IS auditor.
  • D. Internal risk assessment documentation is useful but lacks the independent assurance provided by a SOC report.

SOC 2 Type 2 Report

A Service Organization Control (SOC) 2 Type 2 report evaluates the design and operating effectiveness of a service organization's controls over a period of time, relevant to security, availability, processing integrity, confidentiality, or privacy.

  • Issued by an independent auditor.
  • Covers a specified period (e.g., 12 months).
  • Focuses on non-financial reporting controls.

Memory trick: SOC's Scope Secures Service Organizations' Systems.

More Domain 1: Information System Auditing Process questions