A company undergoes a SOC 2 Type II audit. What distinguishes Type II from Type I?
-
A
Type II tests control effectiveness over a period of time; Type I only tests design at a point in time
-
B
Type II covers more control categories than Type I
-
C
Type II is performed by internal auditors; Type I by external auditors
-
D
Type II applies to cloud providers; Type I applies to on-premises systems