Open cardosec

Case D9FB10 · GRC · L2 Practitioner

SOC 2 Type I vs Type II

Practise as: Explain it · Interview

Interview questionA customer asks for your SOC 2. What is it, and what is the difference between a Type I and a Type II report?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SOC 2 is an AICPA attestation by a CPA firm against the Trust Services Criteria; it is a report, not a certification.
  2. TSC: Security (Common Criteria, mandatory), plus optional Availability, Confidentiality, Processing Integrity, Privacy.
  3. Type I: controls suitably designed at a point in time. Type II: design and operating effectiveness over 3-12 months.
  4. Read the auditor opinion (unqualified vs qualified), exceptions in section 4, and scope/carve-outs of subservice orgs.
  5. Complementary User Entity Controls (CUECs) list what the customer must do for the controls to hold.

If the interviewer pushes back

  • A vendor has a clean SOC 2 but AWS is carved out. What does that mean for your assurance and what else do you request?
  • How would you respond to a Type II exception on access removal as the audited company?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.