Under the carve-out method for subservice organizations in a SOC report, the service auditor:
-
A
Tests the subservice organization's controls directly
-
B
Includes the subservice organization's controls in scope and tests them
-
C
Excludes subservice organization controls from the scope and notes their existence
-
D
Requires the subservice organization to obtain its own SOC report