1/39
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
SOC (1) Engagement
The examination and reporting on controls at a service organization that are likely to be relevant to user entities’ internal control over financial reporting
Restricted to management of the service organization, user entities of the service organization’s system, and the independent auditors of such user entities
It does not include potential users of the service organization
*Assesses controls relevant to financial reporting*
SOC (2) Engagement
The examination and reporting on the security, availability, or processing integrity of a system and the confidentiality or privacy of the information processed by the system
Intended for use by those who have sufficient knowledge and understanding of the service organization, the services it provides, and the system used to provide those services
*Assesses controls relevant to security, availability, processing integrity, confidentiality, or privacy*
SOC (3) Engagement
The service auditor reports on whether controls within the system were effective to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved based on the applicable trust services criteria
Does not include a description of the system and/or a description of the service auditor’s tests of controls and the results thereof
Ordinarily for general users
*Assesses controls relevant to security, availability, processing integrity, confidentiality, or privacy*
SOC for Cybersecurity Engagement
Examine and report on a description of the entity’s cybersecurity risk management program and the effectiveness of controls with that program
SOC for Supply Chain Engagement
Examine and report on an entity’s controls over the security, availability, processing integrity, confidentiality, or privacy of a system used to produce, manufacture, or distribute products
Type (1) SOC Report
A report on the fairness of the presentation of management’s description of the service organization’s system and suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date
Includes management’s description of the service organization’s system, a written assertion by management of the service organization about whether the description is fairly presented and controls are suitably designed as of a specified date, and a report that expresses an opinion
*Covers the system design as of a given point in time*
Type (2) SOC Report
A report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period
Includes management’s description of the service organization’s system, a written assertion by management of the service organization about whether the description is fairly presented and controls are suitably designed/operating effectively throughout a period, and a report that expresses an opinion and includes a description of the tests of controls and results
*Covers both the design and operating effectiveness over a period of time*
True
A SOC 3 report is always issued as a Type 2 report.
True or False?
Confidentiality, Availability, Processing Integrity, Privacy, Security (CAPPS)
What are the five trust services criteria?
2, 3
What 2 types of SOC engagements are trust services criteria applicable for?
COSO Framework
A widely accepted control framework utilized by entities to establish and implement an effective system of internal control and includes five components that are supported by 17 principles
Control Environment, Risk Assessment, Information/Communication, Monitoring, Existing Control Activities (CRIME)
What are the five COSO principles?
No
Does the Security trust services criteria have additional criteria (or a series)?
A Series
The additional criteria for the Availability trust services criteria
Focuses on an entity’s ability to ensure all systems are continuously available as needed by maintaining/monitoring processing capacity, identifying/responding to threats, and ensuring a recovery plan is in place and tested
PI Series
The additional criteria for the Processing Integrity trust services criteria
Includes considerations related to creating, using, and communicating quality information so that objectives will be met regarding product/service specifications, controls for completeness/accuracy, productivity, and system specifications
C Series
The additional criteria for the Confidentiality trust services criteria
Ensures that confidential information is handled appropriately
P Series
The additional criteria for the Privacy trust services criteria
Relates to collecting personal data, obtaining consent when collecting/using that data, using data for specific purposes only, managing access to individuals’ data responsibly, disclosing policies to third parties and individuals properly, maintaining complete/accurate records, and monitoring/enforcing practices in place
Control Activities
Which COSO component includes the trust services supplemental criteria?
Unmodified (Unqualified) Opinion
The service auditor’s opinion that, in all material respects, based on the criteria described in management’s assertion:
Management’s description of the system fairly presents the system that was designed and implemented
The controls stated in management’s description of the system were suitably designed
The controls stated in management’s description of the system operated effectively (Type 2 only)
Complementary User Entity Controls, Complementary Subservice Organization Controls (CUECs, CSOCs)
If the application of these is necessary to achieve the related control objectives stated in management’s description of the service organization’s system, a statement to that effect needs to be made
Complementary Subservice Organization Controls (CSOCs)
Controls implemented at the subservice organization necessary to achieve the control objectives stated in management’s description of the service organization’s system
Complementary User Entity Controls (CUECs)
Controls that are necessary to be implemented by the user entity, in combination with the service organization’s controls, to provide reasonable assurance that the control objectives stated in management’s description of the service organization’s system (SOC 1) or the service organization’s service commitments and system requirements (SOC 2) were achieved
Qualified Opinion
States that except for the effects of the matter(s) giving rise to the modification, the description is presented in accordance with the description criteria and the controls were suitabily designed and operating effectively (Type 2), in all material respects
Material, but not pervasive
Only the opinion section of the report changes for SOC 1, service auditor’s responsibility and opinion sections of the report change for SOC 2
Adverse Opinion
States that the description misstatements, either individually or in the aggregate, are material and pervasive, or deficiencies in the design or operation of controls are material and pervasive
Only the opinion section of the report changes for SOC 1, service auditor’s responsibility and opinion sections of the report change for SOC 2
Disclaimer of Opinion
States that the auditor does not express an opinion
The first sentence of the service auditor’s report is revised to state “We were engaged to examine”
The report omits statements indicating what standards require of the practitioner, that the practitioner believes the evidence obtained is sufficient/appropriate to provide a reasonable basis for the opinion, and describing the nature of the engagement
Inclusive Method
Method of addressing the services provided by a subservice organization in which the description of the service organization’s system includes a description of the nature of the services provided by the subservice organization and the components of their system used to provide services to the service organization
Carve-Out Method
Method of addressing the services provided by a subservice organization in which the CSOCs of the subservice organization are excluded from the description of the service organization’s system and from the scope of the engagement
Identifies the nature of the services performed by the subservice organization and the types of controls expected to be performed at the subservice organization
Description Misstatement
The term used when describing errors or omissions in the description of the service organization’s system
Deviation (Exception)
Identified misstatements resulting from the failure of a control to operate in a specific instance
Deficiency in Design
When a control necessary to meet control objectives is missing or improperly designed so that even if it operates as designed, control objectives would not be achieved
Deficiency in Operating Effectiveness
When a properly designed control fails to operate as designed or when the person performing the control does not possess the competency necessary to perform the control effectively
System
The infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve one or more of the organization’s specific business objectives in accordance with management-specified requirements
“How we do what management says we need to do”
Infrastructure
Individual physical or virtual resources, or a collection of resources, that support a service organization’s environment
May include physical structures or hardware such as buildings, servers, switches, file storage devices, survelliance equipment, mobile devices, and internally or externally connected networks
Software
Applications and programs that support the operations of an IT system such as operating systems, middleware, database structures and retrieval mechanisms, external web-based applications, internally shared applications, and details describing those systems or how they function
System Requirements
Define how the system should function to meet the service commitments, comply with laws and regulations, and achieve other objectives
Nature
How controls are tested
Involves making inquiries and performing other procedures such as inspection, observation, or reperformance to obtain evidence about how the control was applied, the consistency with which the control was applied, by whom or by what means the control was applied, etc
Extent
The number of procedures performed and the size of the sample
Considers the tolerable rate of deviation, expected rate of deviation, the frequency with which the control operates, the relevance/reliability of the evidence, the length of the testing period, significance of control, etc
Timing
When the controls are tested and the frequency of testing
Factors include the period of time during which the information will be available, whether the control leaves a trail, and the significance of the control
Nature, Extent, Timing (NET)
The service auditor is responsible for determining the ____, _____, and _____ of procedures necessary to obtain sufficient and appropriate audit evidence about the operating effectiveness of controls throughout the engagement period.
Subsequent Events
Transactions/events that occur after the engagement period but prior to the date of the service auditor’s report that could have a signficant effect on the description, the suitability of design of controls, the operating effectiveness of controls, or management’s assertion