Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 22 discussion

Actual exam question from ISC's CISSP
Question #: 22
Topic #: 1
[All CISSP Questions]

What industry-recognized document could be used as a baseline reference that is related to data security and business operations or conducting a security assessment?

  • A. Service Organization Control (SOC) 1 Type 2
  • B. Service Organization Control (SOC) 1 Type 1
  • C. Service Organization Control (SOC) 2 Type 2
  • D. Service Organization Control (SOC) 2 Type 1
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Toa
Highly Voted 2 years, 2 months ago
Answer D: The difference between SOC 2 Type i and Soc 2 Type ii reports lies in the period of time each covers. SOC 2 Type 1, often an organization’s first-ever SOC 2 report, looks at internal controls governing data security and privacy at the time of the audit. SOC 2 Type 2 reports discuss the effectiveness of your organization’s information security and privacy controls since your last SOC audit, which typically means one year. The two types of reports are used differently by organizations: SOC 2 Type 1 takes a “snapshot-in-time” approach, setting a baseline for future audits of your service organization’s system. SOC 2 Type 2 asks how well your data security and privacy controls have worked since your last SOC 2 audit. So, the audit procedure most organizations follow is: Type 1 for the first SOC 2 audit Type 2 for subsequent SOC 2 audits. https://reciprocity.com/resources/what-is-a-soc-2-type-2-audit/
upvoted 15 times
jackdryan
1 year, 7 months ago
D is correct
upvoted 1 times
...
...
MSKid
Highly Voted 2 years, 2 months ago
Selected Answer: D
SOC 2 Audits are not shared publicly unless a NDA is given, so this would work for an internal audit that would not be shared outside the organization | Type 1 report would cover a point in time providing a baseline per the question
upvoted 8 times
...
ziyaetuk
Most Recent 2 days, 5 hours ago
Selected Answer: D
The word is "baseline reference". So it's D. It was an elaborate request that will take time, I will go with C. Say you need to demonstrate compliance ASAP because an important enterprise prospect requires it to close the deal. But your company is too young to have formal systems in place, or you’ve recently made major changes to your data security systems. Instead of waiting for a Type 2 report, a Type 1 report that evaluates your information security controls as they stand today can act as a short-term solution, which defines the base-line.
upvoted 1 times
...
M_MUN17
1 month, 1 week ago
The correct answer is C. Service Organization Control (SOC) 2 Type 2. SOC 2 Type 2 is an industry-recognized report that focuses on an organization's controls related to data security, availability, processing integrity, confidentiality, and privacy over a period of time. It provides detailed insights into how an organization maintains security and compliance in these areas, making it an ideal baseline reference for conducting a security assessment or evaluating data security practices. The other options focus on different aspects: SOC 1 reports are primarily concerned with the internal controls over financial reporting (ICFR), not data security. SOC 2 Type 1 assesses the design of controls at a specific point in time, while SOC 2 Type 2 covers both the design and operating effectiveness of controls over an extended period, which is more comprehensive for security assessments.
upvoted 1 times
...
robervalchocolat
2 months, 3 weeks ago
Given that the question asks for a document related to data security and business operations, SOC 2 Type 2 is the most appropriate choice. It provides evidence of the effectiveness of controls related to security, availability, processing integrity, confidentiality, or privacy, which are all critical aspects of data security and business operations.
upvoted 1 times
...
isaphiltrick
3 months ago
Selected Answer: C
SOC 2 Type 2 reports provide a more comprehensive evaluation of an organization’s controls related to security, availability, processing integrity, confidentiality, and privacy. Unlike SOC 2 Type 1, which only assesses the design and implementation of controls at a specific point in time, SOC 2 Type 2 evaluates the operating effectiveness of these controls over an extended period, typically six months to a year. This ongoing assessment offers greater assurance about the reliability and consistency of the controls, making it a better baseline for evaluating data security and business operations.
upvoted 1 times
...
deeden
3 months, 2 weeks ago
Selected Answer: D
Agree with D because of the key word "baseline" Type I can be use as a point in time reference, then observe the system for 6-12 months to complete a Type II report.
upvoted 1 times
...
Vaneck
8 months, 1 week ago
For a basic reference related to data security and business operations or conducting a security assessment, the industry-recognized document that could be used is : **C. Service Organization Control (SOC) 2 Type 2**. SOC 2 reports are designed to assess an organization's controls over the security, availability, processing integrity, confidentiality and privacy of the systems used to process user data. A SOC 2 Type 2 report not only provides a description of the controls in place, but also assesses the effectiveness of these controls over a period of time, offering substantial assurance on how well a company secures data against established trust criteria.
upvoted 1 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: D
Answer D) SOC 2 Type I Sets a baseline for future audits Describes the organization’s system and the suitability of controls Takes a “snapshot-in-time” approach
upvoted 3 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
Among the options provided, the industry-recognized document that could be used as a baseline reference related to data security, business operations, and conducting a security assessment is option C, Service Organization Control (SOC) 2 Type 2. SOC reports are a set of independent audit reports created by the American Institute of Certified Public Accountants (AICPA) to assess the controls and security practices of service organizations. SOC 2 specifically focuses on the Trust Services Criteria, which include security, availability, processing integrity, confidentiality, and privacy.
upvoted 2 times
...
jackdryan
1 year, 7 months ago
D is correct
upvoted 1 times
...
rootic
2 years ago
Selected Answer: D
Answer is D.
upvoted 1 times
...
DButtare
2 years, 2 months ago
Baseline -> Type 1
upvoted 3 times
...
jon1991
2 years, 2 months ago
Selected Answer: D
The answer should be - D - Baseline reference seems to be the keyword here, At specific point in time.
upvoted 5 times
...
N00b1e
2 years, 2 months ago
I think the term "baseline" is crucial in this question. Type two leans more towards "continuous" and results over time, rather than static.
upvoted 3 times
...
stickerbush1970
2 years, 2 months ago
Selected Answer: D
SOC 2 Report examines a service organization’s controls over one or more of the following five standards known as Trust Services Criteria (TSC): • Security • Availability • Processing Integrity • Confidentiality • Privacy 1. Type I report ensures that controls are in place 2. Type II confirms that they’re effective. So, as you can probably guess, a SOC 2 Type II report is the best representation of how well a vendor is managing and safeguarding your data.
upvoted 1 times
...
Eric710
2 years, 2 months ago
I agree. This answer should be C.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...