Certified Cloud Security Professional – CCSP – Question108

Which type of audit report is considered a "restricted use" report for its intended audience?

A.
SAS-70
B. SSAE-16
C. SOC Type 1
D. SOC Type 2

Correct Answer: C

Explanation:

Explanation: SOC Type 1 reports are considered “restricted use” reports. They are intended for management and stakeholders of an organization, clients of the service organization, and auditors of the organization. They are not intended for release beyond those audiences.