The several kinds of SOC reports differ based on what they cover, how the auditor performs the assessment and what level of detail the reports include. This way, the vendor can avoid each client performing their own audit of the vendor’s system. Listen now to learn the differences between a SOC 1 and SOC 2 report and Type 1 and Type 2.
eBook: SOC Dictionary
Infographic: Vendor Risk Management and the SSAE 18 Audit
Welcome to this week’s Third Party Thursday! My name is Lisa Hill and I’m an Information Security Specialist here at Venminder. Today we are going to talk a little about SOC 1 and 2 reports, including what some of the differences are.
Let’s first cover why there are different kinds. Service Organization Control (SOC) reports are auditing reports that are issued in compliance with the SSAE 18 standard. The different kinds of SOC reports differ based on what they cover, how the auditor performs the assessment and what level of detail the reports include. This way, the vendor can avoid each client performing their own audit of the vendor’s system.
That being said, we can expect to see even more kinds of SOC reports in the future. But for now, the two most recognized are SOC 1 and SOC 2. These each have two particular types of their own, Type 1 and Type 2.
Let’s talk about the differences between a SOC 1 and SOC 2 report:
As I mentioned, there are two types of each SOC report. Type 1 and Type 2:
Again, I’m Lisa and thanks for tuning in to this week’s third party Thursday; if you haven’t already done so, please subscribe to our series.