SOC Engagements Flashcards

1
Q

What creates the need for a SOC engagement?

A

When an organization (User Entity) engages in business with other entities (service organizations) to out source key services and business operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why do we need SOC (system and organizational controls) engagements?

A

SOC engagements assess the effectiveness of a service organization’s controls. They result in the issuance of a SOC report and promote reliance by third parties on service organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three main types of SOC engagements and what other types of SOC engagements are available?

A

The three main types of SOC engagements are
1. SOC 1
2. SOC 2
3. SOC 3

In addition, there are SOC engagements specific for Cybersecurity and SOC engagements specific for Supply Chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a SOC 1 engagement for Service Organizations?

A

SOC 1 engagements reports on internal control over financial reporting. The examination and reporting on controls at a service organization that are likely to be relevant to user entities internal control over financial reporting.

Restricted to management of the service organization, user entities of the service organizations system, and independent auditors of such user entities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are SOC 2 engagements?

A

A SOC 2 engagement is an examination and reports on the trust services criteria which are the security, availability, processing integrity of a system, confidentiality and privacy of the information processed by the system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who are the intended users of SOC 2 Service Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Carve Out Method

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly