What is a SOC report?
SOC is a reporting framework that allows cloud providers to communicate the effectiveness of their cybersecurity risk management program to certified public accountants (CPAs) and broad-range stakeholders—customers, among others.
Any organization that provides cloud services should consider complying with the SOC standard. A SOC is made up of the following type of reports:
- SOC 1—A financial statement:
- SOC 1 Type 1—An attestation of controls for a CSP at a specific point in time
- SOC 1 Type 2—An attestation of controls for a CSP and their effectiveness over a minimum 6-month period
- SOC 2—A report of controls relevant to security, availability, integrity, and confidentiality or privacy
- SOC 2 Type 1—A description of cloud providers' systems and suitability of the design of controls
- SOC 2 Type 2—A description of cloud providers' systems and suitability of the design of controls and the effectiveness...