SOC Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under the Gramm-Leach-Bliley Act (GLBA), which SOC report type is most commonly required for financial institutions demonstrating safeguards compliance?
- SOC 1 Type II
- SOC 2 Type II (Correct answer)
- SOC 3
- SOC for Cybersecurity
Correct answer: SOC 2 Type II
SOC 2 Type II is the most commonly referenced report for financial institutions needing to demonstrate compliance with GLBA Safeguards Rule controls over a period of time.
Question 2: Which federal regulation primarily governs the protection of Protected Health Information (PHI) and directly influences SOC 2 engagements for healthcare service organizations?
- FERPA
- GLBA
- HIPAA (Correct answer)
- SOX
Correct answer: HIPAA
HIPAA establishes requirements for safeguarding PHI and directly shapes the privacy and security criteria evaluated in SOC 2 engagements for healthcare-related service organizations.
Question 3: A service organization's SOC 1 report is based on which professional standard issued by the AICPA?
- AT-C Section 105
- AT-C Section 205
- AT-C Section 315 (Correct answer)
- AT-C Section 320
Correct answer: AT-C Section 315
SOC 1 engagements are performed under AT-C Section 315, which addresses examination engagements on controls at a service organization relevant to user entities' internal control over financial reporting.
Question 4: Which of the following best describes a 'carve-out' method in a SOC report?
- Excluding certain Trust Service Criteria from the scope
- Removing a subservice organization from the scope of the service auditor's procedures (Correct answer)
- Omitting prior period comparatives from the description
- Excluding internal audit findings from the report
Correct answer: Removing a subservice organization from the scope of the service auditor's procedures
The carve-out method excludes a subservice organization from the scope of the service auditor's procedures, leaving responsibility for those controls with the user entity.
Question 5: The Children's Online Privacy Protection Act (COPPA) most directly impacts which SOC 2 Trust Service Criterion?
- Availability
- Processing Integrity
- Privacy (Correct answer)
- Confidentiality
Correct answer: Privacy
COPPA governs the collection and use of personal information from children under 13, directly affecting the Privacy criterion in SOC 2 engagements for applicable service organizations.
Question 6: Which party is responsible for preparing the system description included in a SOC 2 report?
- The service auditor
- The user entity
- Management of the service organization (Correct answer)
- The AICPA
Correct answer: Management of the service organization
Management of the service organization is responsible for preparing and asserting on the fairness of the system description included in the SOC 2 report.
Question 7: Under SOX Section 404, which type of SOC report provides the most direct evidence for management's assessment of internal controls over financial reporting at a service organization?
- SOC 2 Type I
- SOC 3
- SOC 1 Type II (Correct answer)
- SOC for Cybersecurity
Correct answer: SOC 1 Type II
SOC 1 Type II provides evidence of the design and operating effectiveness of controls relevant to ICFR over a period, making it most directly useful for SOX 404 compliance purposes.
Under the Gramm-Leach-Bliley Act (GLBA), which SOC report type is most commonly required for financial institutions demonstrating safeguards compliance?