what creates the need for a SOC engagement?
outsourcing
a service organization provides the user entity with what 4 benefits?
personnel
expertise
equipment
technology
what are 6 examples of the types of services provided by service organizations?
payroll services
cloud service providers
credit card processors
enterprise IT outsourcing services
FinTech services
customer support
SOC engagements assess what?
the effectiveness of a service organization’s controls
what are the 3 main types of SOC engagements? what do they focus on?
SOC 1 (internal control over financial reporting (ICFR))
SOC 2 (trust services criteria)
SOC 3 (trust services criteria for general use)
SOC 1 reports are limited to what 3 groups?
management of the service org.
user entities of the service organization’s system
independent auditors of such user entities
SOC 2 reports are limited to what 2 groups?
management
other specified parties (knowledge of the system, the org, and their services)
what 2 things does a SOC 3 report not have that is in a SOC 2?
description of the system
description of the service auditor’s test of controls and results thereof
what are 2 other SOC engagements?
SOC for cybersecurity engagement
SOC for supply chain engagement
SOC reports differ depending on what 2 things?
type of SOC engagement
whether the report issued is a Type 1 or 2 report
what 2 points are included in a Type 1 and 2 report?
what are the 2 differences between a type 1 and 2 report?
a SOC 3 report is always issued as what type of report (type 1 or 2)?
type 2
what 3 things are typically in a type 1 and type 2 report?
type 2 has 2 additions
what are the 5 trust services criteria?
CAPPS
Security
Availability
Processing integrity
Confidentiality
Privacy
what does processing integrity refer to?
system processing is complete, valid, accurate, timely, and authorized to meet the entity’s objectives
a SOC 3 engagement does not have what that a SOC 2 type 2 report has?
description of tests of controls performed by auditor and the results
what are the 5 COSO components?
CRIME
Control environment
Risk assessment
Existing control activities
Information and communication
Monitoring
trust services criteria expands on COSO principle 12 with what 4 criteria?
logical and physical access control
system operations
change management
risk mitigation
what is the only trust service criteria that does not need additional category-specific criteria?
security
what are the 4 additional criteria for trust services?
A series
PI series
C series
P series
what does the A series focus on? what 3 things does it do to ensure this?
an entity’s ability to ensure all systems are continuously available
1) maintaining and monitoring processing capacity
2) identify and respond to threats
3) ensure a recovery plan is in place and tested
the PI series focuses on what?
considerations related to creating, using, and communicating quality information so objectives will be met
what does the C series focus on?
ensuring confidential information is handled appropriately