ISC S4 Flashcards

Review main topics of S4 modules.

1
Q

What does a SOC 1, 2, and 3 report examine?

A

SOC 1: Service organization controls relevant to ICFR
SOC 2: TSC for entities knowledgeable and understanding of SSS
SOC 3: TSC for general use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the difference between Type I and Type II SOC reports?

A

Type I: Design of controls at a point in time
Type II: Design of controls over a period of time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the five TSC and their definitions?

A

Security - Unauthorized access to systems
Availability - Systems and info available for operations
Processing Integrity - System processing (CVATA)
Confidentiality - Safekeeping of info (broad)
Privacy - Safekeeping of personal info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What must a service auditor address in terms of TSC and Additional-Category Specific Criteria ASC?

A

TSC - All
ASC - All except security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What must an entity consider when designing internal controls in terms of TSC?

A

Set outcomes to meet objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is omitted from a SOC Report by the Service Auditor when issuing a Disclaimer of Opinion?

A
  1. Professional standard requirements
  2. Obtained sufficient and appropriate audit evidence
  3. Description of an examination engagement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly