SOC Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: The EU General Data Protection Regulation (GDPR) concept of 'data processor' most closely maps to which SOC framework role?
- User entity
- Service organization (Correct answer)
- Subservice organization
- Service auditor
Correct answer: Service organization
Under GDPR, a data processor processes personal data on behalf of a controller, which parallels the service organization role in a SOC engagement that processes data for user entities.
Question 2: Which AICPA standard governs SOC 2 and SOC 3 attestation engagements?
- AT-C Section 205 (Correct answer)
- AT-C Section 315
- AT-C Section 320
- SAS No. 70
Correct answer: AT-C Section 205
AT-C Section 205 (Examination Engagements) is the primary attestation standard governing SOC 2 and SOC 3 engagements performed by CPAs.
Question 3: A cloud provider subject to FedRAMP is most likely to reference which SOC report in their compliance documentation to satisfy federal agency requirements?
- SOC 1 Type I
- SOC 2 Type II (Correct answer)
- SOC 3
- SOC for Cybersecurity
Correct answer: SOC 2 Type II
FedRAMP-authorized cloud providers commonly use SOC 2 Type II reports as supplementary evidence of security control effectiveness to federal agency customers.
Question 4: Which of the following scenarios would most likely result in a qualified opinion in a SOC 2 report?
- A single minor control deviation with no impact
- Management's description is fairly presented but one criterion is not met
- The auditor is unable to assess availability controls due to scope limitation (Correct answer)
- The report covers a 12-month period instead of 6 months
Correct answer: The auditor is unable to assess availability controls due to scope limitation
A scope limitation that prevents the auditor from evaluating a criterion would result in a qualified or disclaimer of opinion in the SOC 2 report.
Question 5: Under the California Consumer Privacy Act (CCPA), a service organization acting as a 'service provider' must include which element in its contracts with businesses?
- A right to audit clause enforceable by regulators
- A prohibition on selling personal information received from the business (Correct answer)
- A mandatory data breach notification within 24 hours
- An obligation to respond to consumer requests directly
Correct answer: A prohibition on selling personal information received from the business
CCPA requires that contracts with service providers include a prohibition on selling the personal information they receive, a key compliance requirement for service organizations handling California consumer data.
Question 6: In a SOC engagement, 'complementary user entity controls' (CUECs) are best described as:
- Controls the service organization performs on behalf of user entities
- Controls the auditor tests at the user entity location
- Controls user entities must implement for the service organization's controls to function effectively (Correct answer)
- Supplemental controls added by the subservice organization
Correct answer: Controls user entities must implement for the service organization's controls to function effectively
CUECs are controls that management of the service organization assumes will be implemented by user entities, and both parties need them in place for the overall control environment to be effective.
Question 7: Which regulatory framework introduced the concept of 'Cybersecurity Maturity Model Certification' (CMMC) relevant to defense contractors evaluating SOC reports?
- NIST SP 800-53
- DFARS/CMMC (Correct answer)
- ISO 27001
- FedRAMP
Correct answer: DFARS/CMMC
DFARS (Defense Federal Acquisition Regulation Supplement) and its CMMC requirement govern cybersecurity standards for Department of Defense contractors, who may leverage SOC 2 reports as supporting evidence.
The EU General Data Protection Regulation (GDPR) concept of 'data processor' most closely maps to which SOC framework role?