Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 84
We are using Service Organization Control (SOC) reports. We want the report to be only released when signing an NDA, and it should be able to report on security, availability, processing integrity, confidentiality, or privacy controls. Which report should we use?
- A SOC 3
- B SOC 1
- C SOC 2
- D SOC 4
Reveal correct answer
Correct answer: C
Explanation
The correct answer: The SOC 2 report is the best choice here. It is specifically designed to address controls at a service organization relevant to the security, availability, and processing integrity of a system, as well as the confidentiality and privacy of the information processed by the system. SOC 2 reports contain sensitive information, so they are usually only distributed to specified parties who have signed a Non-Disclosure Agreement (NDA). The incorrect answers: A SOC 1 report focuses on the controls at a service organization that are relevant to an audit of a user entity’s financial statements. While they are a useful tool for management and auditors, they do not cover the same breadth of information systems controls as a SOC 2 report. A SOC 3 report covers the same areas as a SOC 2 report, but it is a general-use report that can be distributed freely and even posted on the service provider's website. It does not contain the same level of detailed information and is not restricted to parties who have signed an NDA. There is no such report as SOC 4. The SOC reporting system only includes SOC 1, SOC 2, and SOC 3 reports.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
