Certified Information Systems Security Professional CISSP · Free Practice Question Easy

Question 84

We are using Service Organization Control (SOC) reports. We want the report to be only released when signing an NDA, and it should be able to report on security, availability, processing integrity, confidentiality, or privacy controls. Which report should we use?
  • A SOC 3
  • B SOC 1
  • C SOC 2
  • D SOC 4
Reveal correct answer

Correct answer: C

Explanation

The correct answer: The SOC 2 report is the best choice here. It is specifically designed to address controls at a service organization relevant to the security, availability, and processing integrity of a system, as well as the confidentiality and privacy of the information processed by the system. SOC 2 reports contain sensitive information, so they are usually only distributed to specified parties who have signed a Non-Disclosure Agreement (NDA). The incorrect answers: A SOC 1 report focuses on the controls at a service organization that are relevant to an audit of a user entity’s financial statements. While they are a useful tool for management and auditors, they do not cover the same breadth of information systems controls as a SOC 2 report. A SOC 3 report covers the same areas as a SOC 2 report, but it is a general-use report that can be distributed freely and even posted on the service provider's website. It does not contain the same level of detailed information and is not restricted to parties who have signed an NDA. There is no such report as SOC 4. The SOC reporting system only includes SOC 1, SOC 2, and SOC 3 reports.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need