Security Assessment Standards and Frameworks - SOC Reports

9 slides · 3 min read · Domain 6

Security Assessment Standards and Frameworks SOC Reports

Service Organization Control (SOC) Reports

The American Institute of Certified Public Accountants' (AICPA) framework for evaluating internal controls over financial reporting is best known by its System and Organization Control (SOC, pronounced "sock") reports that evaluate organizational controls against a set of five Trust Services Principles.

AICPA issues what are called Statements on Standards for Attestation Engagements (SSAEs), which act as compliance standards for AICPA-certified auditors to use when they are contracted (engaged) by an organization to review and report (attest) to that organization's effective use of internal controls over financial reporting (ICFR).

The SOC framework established by SSAE 18 (updated in part by SSAE 20) defines two major report types

SOC 1: Attests to the condition of the organization's ICFR. There are two different types of reports:

  • SOC 1 Type l audits the performance of a set of controls at a particular point in time.
  • SOC 1 Type II reports on the performance of controls over a specified period.

Normally, the SOC 1 Type Il reports are preferred, as they are testing, assessing, and auditing the use and performance of ICRs at multiple points during the period of assessment.

SOC 2: These are known as the Trust Services Criteria Principles. AICPA defines these to be:

  • Security
  • Availability
  • Confidentiality
  • Processing Integrity
  • Privacy

SOC 2 also has two types:

  • SOC 2 Type I verifies the design of controls within the organization, at the time of the report's assessment.
  • SOC 2 Type II goes further, assessing whether the controls are working effectively. These reports are usually based on observations over a specified period.

Because of its focus on the Trust Services Criteria Principles and its assessment of their effective use over a particular period, a SOC 2 report can be quite valuable to the organization, and to its customers. This is especially true for organizations that are, by nature, primarily service providers.

  • SOC 3 reports provide a summary of the findings and attestations of a SOC 2 report, in less technical form. This means that the SOC 3 report is designed to be a publicly releasable summary statement of how well the service provider meets the Trust Services Criteria Principles. They are often found on public-facing pages on service providers' websites.
  • SOC for Cybersecurity: This report focuses specifically on the cybersecurity plans, programs, processes, procedures, services or functions used by the organization to meet its cybersecurity requirements. It uses the 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy as its basis.

Text on this slide

Report

SOC 1

SOC 2

SOC 3

SOC for Cybersecurity Type 1

SOC 1 Point in Time (Initial Baseline)

Point in Time (Initial Baseline)

Single type

Single type Type 2

Performance over time (6 months recommended minimum, generally annual)

Performance over time (6 months recommended minimum, generally annual)

Single type

Single type

SOC Reports

Focus

Internal Control over Financial Reporting (ICOFR)

Security Controls

General summary of SOC 2

Trust Services Criteria applicable to Cybersecurity

Type 1 vs. Type 2 SOC Reports

The earlier SAS 70 standard consisted of Type I and Type Il audits. This has been carried over to the SOC 1 and SOC 2 audit reports.

Under either standard, both types of reports consider the following:

  • Fairness of the presentation of management's description of the service organization's systems).
  • Suitability of the design of the controls to achieve the related control objectives.
  • All of this as of a specified date.
  • SOC 2 reports add one important element: they evaluate the operating effectiveness of these controls.

One can read the SOC 1 report as an expression of due care (does the service organization have the right plans and processes in place), and the SOC 2 report as reviewing their due diligence (how do they know the controls are still working correctly).

Test this domain