Home > Glossary > Certified Information Systems Security Professional > System and Organization Controls (SOC) 2

📖 What is System and Organization Controls (SOC) 2?

System and Organization Controls (SOC) 2 is an auditing procedure that ensures service providers securely manage data to protect the interests of their organization and the privacy of their clients. It is based on Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

🥋 Sensei Says:

"Distinguish between Type I (design of controls at a point in time) and Type II (operational effectiveness of controls over a period of time)."

📚 Certification: Certified Information Systems Security Professional (CISSP)

🔑 What are the Key Concepts of System and Organization Controls (SOC) 2?

  • The Trust Services Criteria (TSC) define the framework, focusing on security, availability, processing integrity, confidentiality, and privacy to evaluate a service provider's control environment.
  • SOC 2 Type I reports assess the design of controls at a specific point in time, confirming that the necessary security measures are in place.
  • SOC 2 Type II reports evaluate the operational effectiveness of controls over a period, typically six months, proving that the controls function as intended.
  • These reports provide third-party attestation from a CPA, reducing the need for every individual client to perform their own onsite audit of the provider.
  • Unlike SOC 1, which focuses on financial reporting, SOC 2 is specifically designed for technology-based service organizations managing sensitive customer data.

🎯 How does System and Organization Controls (SOC) 2 appear on the CISSP Exam?

You may be asked to determine which report to request when a company requires evidence that a cloud vendor's security controls have been consistently applied and operating effectively over the last twelve months.

A scenario might describe a vendor who has just implemented a new security framework and needs a quick attestation of their control design at a specific point in time before a major client launch.

Expect questions where you must distinguish between SOC 1, 2, and 3, specifically identifying SOC 2 as the appropriate choice for evaluating a SaaS provider's security posture and privacy controls.

❓ Frequently Asked Questions

How does SOC 2 differ from SOC 1?

SOC 1 is focused on controls relevant to a client's financial reporting. SOC 2 is broader, focusing on the Trust Services Criteria, making it the standard for security and privacy audits of cloud service providers.


Why is a Type II report preferred over a Type I report during vendor risk management?

A Type I report only confirms that a control is designed correctly at one moment. A Type II report proves the control was actually operated and remained effective over a period of time.

Related Terms from Certified Information Systems Security Professional

📝 Related Study Guides

Study Guide 10 min read

How to Pass the CISSP Exam: A Realistic 2026 Study Plan

To pass the CISSP, you must transition from a technical mindset to a managerial one, focusing on risk management and policy over implementation. Success requires a 3-6 month study plan covering all eight domains, using adaptive practice exams to identify gaps and mastering the "mile wide, inch deep" breadth of the CBK.

Career Guide 10 min read

CISSP Experience Requirements: How to Get Your Waiver in 2026

To earn the CISSP, you need five years of cumulative, paid work experience in two or more of the eight CISSP domains. You can obtain a one-year waiver through a four-year college degree or approved professional certifications. Those lacking full experience can become an Associate of ISC2 after passing the exam.

Deep Dive 8 min read

Kerberos Authentication Explained for the CISSP Exam

Kerberos is a ticket-based authentication protocol designed to provide strong authentication for client/server applications by using secret-key cryptography. It utilizes a trusted third party called the Key Distribution Center (KDC) to issue tickets, enabling Single Sign-On (SSO) and preventing replay attacks through the use of synchronized timestamps.

🧠

Test Your Knowledge

Think you understand System and Organization Controls (SOC) 2? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium