For businesses considering a cloud computing solution, which of the following should they ask the cloud vendor to provide before entering into a contract for critical business operations?
FASB 51 Report.
SOC 1 Report.
SAS 3 Report.
SOC 2 Report.
The correct answer is "SOC 2 Report".
Reason: There are 3 types of SOC reports:
1. SOC 1 Report: This report is used to check controls over the financial transaction processing for their completeness and accurcy. This report does not deal with reliability of the system secruity.
2. SOC 2 Report: This report is used to verify the integrity and accuracy of the systems and the information they contain and process.
3. SOC 3 Report: It is pretty much the same as SOC 2 report, however they remove the test results from the report as it is meant for public distribution.
It is clear from the meaning of all the reports above that if you are looking for comfort over the financial reporting process you need to obtain SOC 1 Report from the vendor, however, if you are looking for comfort over system such as a cloud computing solution, you need to obtaina SOC 2 report from the vendor.
Get Answers For Free
Most questions answered within 1 hours.