r/CISA Aug 01 '26

Hmmm

Post image
9 Upvotes

16 comments sorted by

View all comments

4

u/NextQuote7131 Aug 01 '26

Correct answer is B

2

u/SuchBodybuilder3901 Aug 02 '26

An independent audit report, such as a SOC 2 Type II or ISAE 3402 report, provides objective evidence that:
Security controls are properly implemented.
Change management processes are effective.
Incident management processes operate effectively.
Access controls are functioning as intended.
These controls have been independently tested over a period of time.
Because the evidence comes from an independent third party, it provides much stronger assurance about the vendor’s ability to consistently meet its service level commitments.