StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 6: Security assessment & testing

Conducting or facilitating security audits: SOC 1/SOC 2/SOC 3, Type I vs Type II

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

When an organization relies on a service provider such as a payroll processor, cloud host or data center, it usually cannot audit that provider's controls itself. It would be impractical for thousands of customers to send auditors to the same provider. Instead, the provider engages an independent auditor to evaluate its controls and issue a report that customers can rely on. These are System and Organization Controls (SOC) reports, issued by certified public accountants under attestation standards from the American Institute of Certified Public Accountants (AICPA). Internationally, a similar attestation exists under the ISAE 3402 standard. The exam focuses on the three SOC report types and on Type I versus Type II.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan