A hosting provider needs to prove that its security controls have been in place over the last six months and have sufficiently protected customer data. Which of the following would provide the best proof that the hosting provider has met the requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: SOC 2 Type 2 report.
Why this is the answer
A SOC 2 Type 2 report provides an independent auditor's opinion on the effectiveness of a service organization's controls over a specified period (typically six months or more). This report specifically addresses security, availability, processing integrity, confidentiality, and privacy, making it ideal for demonstrating that security controls have been in place and effective in protecting customer data over time. NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) is a framework for managing cybersecurity risk, not an attestation of control effectiveness. CIS Top 20 compliance reports indicate adherence to a set of critical security controls but don't provide an independent audit of their operational effectiveness over time. A vulnerability report identifies weaknesses at a specific point in time but doesn't confirm the continuous operation and effectiveness of security controls.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed