SOC 1, SOC 2 and SOC 3 report
Service Organization Control (SOC1, SOC2, SOC3)
There are three new reports established as the framework for examining controls in a service organization, appropriately called SOC (Service Organization Control). While the SOC 1 report is primarily concerned with examining controls over financial reporting, the SOC 2 and SOC 3 reports focus more on standardized and predefined benchmarks for controls related to the security, processing integrity, confidentiality or privacy of the data center system . SOC 2 examines the details of data center testing and operational effectiveness.
These reports are very detailed and useful for:
- Organization supervision
- Supplier management programs
- Internal corporate governance and risk management processes
- Regulatory supervision
SOC 3 is for public use and offers the highest level of certification and guarantee of operational excellence that a data center can receive. A SOC 2 report includes auditor's tests and results, while SOC 3 provides a description of the system and the auditor's opinion.
For further clarification, consult one of our offices.