Sets the criteria needed for SOC 2 audits
American Institute of Certified Public Accountants (AICPA)
SOC 2 criteria that includes controls surrounding HR processes and training
CC1 - Control Environment
This report includes Control Objectives and Control Activities, while this report includes Trust Services Criteria
SOC 1, SOC 2 reports
AWS is utilized to host servers
Complementary Subservice Organization Control (CSOC)
A type 1 report covers a period of time
False. Type 2 reports cover an audit period.
The Company who provides a service/product (the System) that is the subject of the SOC audit.
Service Organization
SOC 2 criteria that includes controls surrounding the change control and system development processes
CC8 - Change Control
Report on management’s description of a service organization’s system and the suitability of the design of controls
Type 1 Report
The SOC 2 type 2 audit period is May 1, 2022 through April 30, 2023. Per discussion with management, the performance and capacity monitoring solution was replaced in October 2022.
Change to the control environment
The SOC 2 criteria CC3 would include controls specific to vendor management and risk assessments
True
The customer of the service organization using the service/product.
User Entity
SOC 2 criteria that includes controls surrounding the business continuity/disaster recovery process
CC9 - Risk Mitigation
This section is typically used for management to provide responses to identified exceptions within type 2 reports.
This section is also used to detail HIPAA mapping and additional information the Company would like to add to the report.
Section V. Additional Information Provided By The Company
User entities are responsible for managing user access and assigned roles to the systems.
Complementary User Entity Control (CUEC)
The SOC 2 Trust Services Criteria include the following:
- Availability
- Processing Integrity
- Confidentiality
- Change Control
- Security
- Privacy
False. Change Control is not a Trust Services Criteria. However, change control is included within the Security Trust Services Criteria.
A third-party of the service organization who directly assists in the delivery of the product/service.
Subservice Organization
SOC 2 criteria that includes controls surrounding the Company's event log management and performance and capacity monitoring tools
CC4 - Monitoring Activities
This section is included within the report and send to management to review and sign on the Company's letterhead.
Management Assertion
While completing testing for a SOC 2 type 2 report, it was noted that 2 of the 20 sampled employees were hired after the annual security awareness training was performed.
Resampling
You are completing testing for a SOC 2 type 1 report. The control states: "All new employees are required to acknowledge the Code of Business Conduct and Ethics."
You should then select a sample of new hires to test they acknowledged the Code of Business Conduct and Ethics upon their hire.
False. During a type 1 audit, you should confirm a recent example new hire acknowledged the Code of Business Conduct and Ethics upon their hire (prior to the report as of date). Sampling is required for type 2 reports.
Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting
SOC 1 Report
SOC 2 criteria that includes controls surrounding the incident response process
CC7 - System Operations
The client is responsible for completing this section of the report and Wolf is responsible for reviewing and providing feedback to ensure it is accurate and all components are included within the testing.
III. System Description
AWS is responsible for maintaining the physical security controls of its data centers. Testing includes adding a CSOC control and reviewing evidence of the Company's periodic vendor assessment.
CSOC carve out method
All SOC 2 reports must include the security criteria.
True