A2 Flashcards
SOC 1 report?
Focuses on internal controls of a company and is made for users that know about the company like management.
SOC 2 report?
Focuses on financial reporting and is distributed to knowledge people of the company for example management.
SOC 3 report?
Type 1
Focuses on design of controls in a point in time
Type 2
Focuses on design and operating effectiveness over a period of time.
Trust service criteria?
If the company meets these goals they will meet their objectives. (confidentiality, availability, processing integrity, privacy, and security)
Set forth the outcomes that an entity’s controls should meet to achieve the entity’s objectives.
Availability?
Ensuring information and systems are available for operation and use to meet the entity’s objectives.
What engagements used Trust service criteria?
Processing integrity?
Ensuring system processing is complete, valid, accurate, timely, and authorized to meet the entity’s objectives.
Control activities?
Ensure the proper application of policies and procedures that help ensure management directives and control objectives are met.
Control environment?
Which covers control from the perspective of the board and management through integrity, ethics, the proper corporate structure, and establishing an environment that holds employees accountable.
Disclaimer Opinion?
Management does not provide the required information to complete the financials.
Adverse opinion?
A mistake that is material and pervasive, so it occurs often.
Qualifies Opinion?
Material misstatement but not pervasive so it doesn’t occur often.
Unmodified Opinion?
No material deficiencies.