A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report. Which statement BEST describes the difference?
-
A
ISO 27001 is US-specific; SOC 2 is international
-
B
ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period
-
C
SOC 2 is a certification; ISO 27001 is an audit report
-
D
Both certifications are identical in scope and value