ISC — Quick Sheet
SOC Engagements
Read time: ~5 minutes
One-minute revision
- SOC 1 = ICFR-relevant controls; SOC 2 = Trust Services Criteria (restricted); SOC 3 = general use summary
- TSC: Security (always required), Availability, Processing integrity, Confidentiality, Privacy
- Type 1 = design at a point in time; Type 2 = design + operating effectiveness over a period
- Only Type 2 supports reliance for a period
- Report contents: auditor's report, management assertion, system description, tests & results (Type 2)
- User auditor never references the service auditor in an unmodified opinion