An auditor is evaluating the effectiveness of a company's security controls for a cloud-based service provider. The audit's scope is focused on controls related to security, availability, processing integrity, confidentiality, and privacy. Which of the following audit reports would be the most relevant for this evaluation?
-
A
ISO 27001 Certification
-
B
PCI DSS Report on Compliance (ROC)
-
C
SOC 2 Type 2 Report
-
D
NIST SP 800-53 Assessment Report