An organization discovers that a third-party subprocessor experienced a breach exposing customer data. Under SOC 2, what is the service organization's primary responsibility?
-
A
The service organization has no responsibility since the breach occurred at the subprocessor level
-
B
Notify affected customers and regulators in accordance with its incident response and breach notification commitments
-
C
Immediately terminate the subprocessor contract without further investigation
-
D
Submit a new SOC 2 audit request to cover the subprocessor's environment