SOC 3: A report on the service organization’s controls that is intended for public use and includes a summary of the organization’s controls and the independent auditor’s opinion on the effectiveness of the controls. It is used to provide transparency to customers and stakeholders about the service organization’s controls. Examples of organizations that may issue a SOC 3 report include cloud service providers and managed IT service providers.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D3: Information Security Program | CISSP D6: Security Assessment and Testing | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index