Terms
Common Criteria
Reporting
What is this an example of?
True or False?
100

Sets the criteria needed for SOC 2 audits

American Institute of Certified Public Accountants (AICPA)

100

SOC 2 criteria that includes controls surrounding HR processes and training

CC1 - Control Environment

100

This report includes Control Objectives and Control Activities, while this report includes Trust Services Criteria

SOC 1, SOC 2 reports

100

AWS is utilized to host servers

Complementary Subservice Organization Control (CSOC)

100

A type 1 report covers a period of time 

False. Type 2 reports cover an audit period. 

200

The Company who provides a service/product (the System) that is the subject of the SOC audit.

Service Organization

200

SOC 2 criteria that includes controls surrounding the change control and system development processes

CC8 - Change Control

200

Report on management’s description of a service organization’s system and the suitability of the design of controls

Type 1 Report

200

The SOC 2 type 2 audit period is May 1, 2022 through April 30, 2023. Per discussion with management, the performance and capacity monitoring solution was replaced in October 2022. 

Change to the control environment

200

The SOC 2 criteria CC3 would include controls specific to vendor management and risk assessments 

True

300

The customer of the service organization using the service/product.

User Entity

300

SOC 2 criteria that includes controls surrounding the business continuity/disaster recovery process

CC9 - Risk Mitigation

300

This section is typically used for management to provide responses to identified exceptions within type 2 reports. 


This section is also used to detail HIPAA mapping and additional information the Company would like to add to the report. 

Section V. Additional Information Provided By The Company

300

User entities are responsible for managing user access and assigned roles to the systems.

Complementary User Entity Control (CUEC)

300

The SOC 2 Trust Services Criteria include the following:


- Availability

- Processing Integrity

- Confidentiality

- Change Control

- Security

- Privacy

False. Change Control is not a Trust Services Criteria. However, change control is included within the Security Trust Services Criteria. 

400

A third-party of the service organization who directly assists in the delivery of the product/service.

Subservice Organization

400

SOC 2 criteria that includes controls surrounding the Company's event log management and performance and capacity monitoring tools

CC4 - Monitoring Activities

400

This section is included within the report and send to management to review and sign on the Company's letterhead.

Management Assertion

400

While completing testing for a SOC 2 type 2 report, it was noted that 2 of the 20 sampled employees were hired after the annual security awareness training was performed.

Resampling

400

You are completing testing for a SOC 2 type 1 report. The control states: "All new employees are required to acknowledge the Code of Business Conduct and Ethics."


You should then select a sample of new hires to test they acknowledged the Code of Business Conduct and Ethics upon their hire.

False. During a type 1 audit, you should confirm a recent example new hire acknowledged the Code of Business Conduct and Ethics upon their hire (prior to the report as of date). Sampling is required for type 2 reports.

500

Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting

SOC 1 Report

500

SOC 2 criteria that includes controls surrounding the incident response process

CC7 - System Operations

500

The client is responsible for completing this section of the report and Wolf is responsible for reviewing and providing feedback to ensure it is accurate and all components are included within the testing. 

III. System Description

500

AWS is responsible for maintaining the physical security controls of its data centers. Testing includes adding a CSOC control and reviewing evidence of the Company's periodic vendor assessment. 

CSOC carve out method

500

All SOC 2 reports must include the security criteria.

True

M
e
n
u