Certification Flashcards

(13 cards)

1
Q

SOC reports demonstrate an organization’s level of assessing _____ and implementing ____ to address ____

A

assessing vulnerabilities/risks, and implementing internal controls to address those risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A SOC attestation is a signed report produced by a _____

A

Certified Public Accountant (CPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Difference between SOC 1 and SOC 2

A

SOC 1 report is geared towards financial reporting controls, SOC 2 is geared towards operational risk and data protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A SOC 1 audit is based on the TSCs. What is this and what are the 5? SAP(I)CP

A

Trust Services Criteria - focus areas to address as deemed appropriate to the organization based on identified risks.

Security is the only criteria required

Optional include:
Availability
Processing Integrity
Confidentiality
Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SOC 1 is designed for companies offering services that directly impact:

A

Financial reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Type I vs. Type II

A

Type 1 typically first step - takes a snapshot of your controls at a point in time. type 2 assesses those controls over a period of time. Typical is 12 months, but we can support 3, 6, 9, 12.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SOC 2 report focuses on how an organization implements/manages controls for what parts of an organization?

A

controls that mitigate identified risks across different parts of the org, operational risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How to prepare for a SOC 1 audit? 5 steps.

A
  1. Define scope - entire org or specific departments?
  2. take inventory of information systems - servers routers etc. so auditors can get understanding of scope of the assessment
  3. Readiness assessment - identify gaps in the controls environment and remediate prior to audit
  4. control objectives
  5. Continuous monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

SOC 1 and 2 services A-LIGN offers:

A

SOC 1 and 2 readiness, type 1 cert, and type 2 cert.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

If you were looking at additional framework certifications - such as ISO42001 or PCI DSS - we can add value in 3 ways. Plus other value:

A
  1. cost consolidation
  2. time and effort savings with A-SCEND/audit harmonization
  3. help with international regulation requirements like GDPR, and mapping overlaps with frameworks like ISO27001.

scalable services in both SOC and ISO, and Pen Testing

breadth of partnerships with GRC tools as well as readiness services providers, continuous monitoring services, etc. - we can help point you in the right direction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Is Pen Testing required for ISO 21007?

A

Not explicitly but strongly recommended as a risk assessment / controls for vulnerability management and security testing - Annex A controls - and demonstrating your commitment to continued improvement, key component of ISO 27001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ISAE 3402 and CSAE 3416

A

equivalent to SOC 1 but for international standards or Canadian standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

GDPR

A

Services to understand

How well did you know this?
1
Not at all
2
3
4
5
Perfectly