Question: Considering the SOC framework, what distinguishes a Type 2 report from a Type 1 report for both SOC - 1 and SOC - 2 audits?
Considering the SOC framework, what distinguishes a Type report from a Type report for both SOC and SOC audits?
Question options:
A
Type reports are only used for SOC audits, not for SOC audits.
B
Type reports evaluate the service provider's physical security measures, while Type reports focus on cyber security.
C
Type reports assess the design of a service provider's controls at a specific point in time, while Type reports evaluate the effectiveness of those controls over a period of time.
D
Type reports are intended for public release, whereas Type reports are confidential and only shared with specific clients.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
