Chapter 6 – Responsibilities in the Cloud Flashcards

1
Q

What are SOC reports?

A

SOC reports are part of the SSAE reporting format by the AICPA; recognized as being acceptable for regulatory purposes, specifically designed for SOX.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is SOC 1?

A

SOC 1 reports are for the auditing of financial reporting instruments of a corporation; there are 2 subclasses (Type 1 and Type 2).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is SOC 2?

A

SOC 2 report audits any controls on an organization’s security, availability, processing integrity, confidentiality, and privacy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Type 1 in SOC reports?

A

Type 1 is not useful for determining security and trust of an organization; it only reviews the design of controls, not how they are implemented, maintained, or functioned.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Type 2 in SOC reports?

A

Type 2 is useful for getting a true assessment of an organization’s security posture; it is extremely detailed and usually not shared unless an NDA is signed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is SOC 3?

A

SOC 3 reports are designed to be shared with the public; they serve as a ‘seal of approval’ and have no data about the security controls, only an assertion that the audit was conducted and passed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly