SOC 2: A set of standards for evaluating the security, availability, processing integrity, confidentiality, and privacy of a service organization’s controls. It is used to assess the internal controls of a service organization. Examples of organizations that may undergo a SOC 2 audit include cloud service providers and managed IT service providers.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D3: Information Security Program | CISSP D6: Security Assessment and Testing | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
Related Articles: