Compliance

SOC 2

English

Overview

An internationally recognized assurance standard for evaluating internal controls around information security.

Details

A US-originated assurance standard that evaluates a service organization's internal controls from perspectives such as security, availability, and confidentiality. It comes in two flavors: Type I, which assesses controls at a single point in time, and Type II, which evaluates how they actually operated over a period (typically six months or more) -- Type II carries more weight as proof the controls really work.

More Security terms