Markdown

SOC

SOC is the Acronym for Service Organization Control

A type of audit framework that assesses a service organization's internal controls, SOC reports are based on standards developed by the American Institute of Certified Public Accountants (AICPA). These reports are intended for service organizations that provide information systems as a service to other organizations, helping to build trust between service organizations and their clients.

History of SOC Reports

The evolution of SOC reports includes several key milestones:

  • SAS 70 (before 2011): The original standard for assessing service organizations' internal controls, focusing on financial reporting.
  • SSAE 16 and SOC 1 (2011-2017): Replaced SAS 70, providing a more comprehensive approach to assessing financial reporting controls.
  • SSAE 18 and SOC 1 (2017-present): Enhanced guidance for performing and reporting on examinations, reviews, and agreed-upon procedures engagements.
  • SOC 2 (2011-present): Focuses on non-financial reporting controls related to security, availability, processing integrity, confidentiality, and privacy.
  • SOC 3 (2011-present): Simplified versions of SOC 2 reports designed for a general audience.
  • SOC for Cybersecurity (2017-present): Addresses cybersecurity risks and the effectiveness of an organization's cybersecurity risk management program.
  • SOC for Supply Chain (2020-present): Assesses risks associated with an organization's supply chain, ensuring the integrity and resilience of production, manufacturing, and distribution processes.

Trust Service Criteria

SOC reports focus on controls grouped into five categories called Trust Service Criteria, established by the AICPA through its Assurance Services Executive Committee (ASEC) in 2017. These criteria are used by Certified Public Accountants (CPAs) to evaluate and report on the controls of information systems.

  • Security: Protects information and systems against unauthorized access, disclosure, and damage.
  • Availability: Ensures that information and systems are available for operation and use as committed or agreed.
  • Processing Integrity: Ensures that system processing is complete, valid, accurate, timely, and authorized.
  • Confidentiality: Protects information designated as confidential.
  • Privacy: Ensures that personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice and with criteria set forth in generally accepted privacy principles (GAPP).

Additional Acronyms for SOC

  • SoC - System on a Chip
  • SOC - Security Operations Center
  • SoC - Separation of Concerns

Articles Tagged SOC

View Additional Articles Tagged SOC