Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CISSP Exam - Topic 7 Question 118 Discussion

Which reporting type requires a service organization to describe its system and define its control objectives and controls that are relevant to users internal control over financial reporting?
B) Service Organization Control 1 (SOC1)
A) Statement on Auditing Standards (SAS)70
C) Service Organization Control 2 (SOC2)
D) Service Organization Control 3 (SOC3)

ISC2 CISSP Exam - Topic 7 Question 118 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 118
Topic #: 7
[All CISSP Questions]

Which reporting type requires a service organization to describe its system and define its control objectives and controls that are relevant to users internal control over financial reporting?

Show Suggested Answer Hide Answer
Suggested Answer: B

Service Organization Control 1 (SOC1) is a report that provides information about the controls at a service organization that may affect the user entities' internal control over financial reporting. It is intended for users who have a reasonable understanding of the nature and significance of the service provided, the service organization's system, and the applicable trust services criteria. A SOC 1 report can help an organization evaluate the effectiveness of the service organization's controls that are relevant to users internal control over financial reporting.


Contribute your Thoughts:

0/2000 characters
Alonzo
2 hours ago
I’m a bit confused; I thought SOC3 was just a summary report. I need to double-check which one really focuses on internal controls.
upvoted 0 times
...
Sharika
5 days ago
SOC2 sounds familiar too, but I believe that's more about data security and privacy rather than financial reporting.
upvoted 0 times
...
Junita
10 days ago
I remember practicing a question about SAS 70, but I think SOC1 is the one that specifically addresses control objectives for financial reporting.
upvoted 0 times
...
Erasmo
16 days ago
I think it might be SOC1 because it focuses on internal controls related to financial reporting, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel