Which SOC 2 principle requires that a service organization's controls operate effectively over the entire review period rather than just at a point in time?
-
A
Point-in-time attestation
-
B
Period-of-time (Type 2) reporting
-
C
Bridge letter coverage
-
D
Complementary user entity controls