Security · Flashcard
What does a SOC 2 Type 2 report cover that a Type 1 does not?
Why this is the answer
Both reports cover the system description and the suitability of the controls' design; only a Type 2 adds testing of operating effectiveness over a period, typically three to twelve months, which is why a customer's risk team asks for Type 2. Design suitability appears in both. So does the fairness of the system description. And management's written assertion is a precondition of any attestation engagement, not something Type 2 introduces.
Read more in the docsMore Compliance as Code flashcards
- What does compliance as code express that a scheduled scan alone does not?
- Why can kube-bench not report control-plane checks on an EKS or GKE cluster?
- Which requirement does the restricted Pod Security Standard add on top of baseline?
- What can S3 Object Lock in compliance mode do that governance mode cannot?
