Certified Cloud Security Professional (CCSP) — Question 114

SOC Type 1 reports are considered "restricted use," in that they are intended only for limited audiences and purposes.
Which of the following is NOT a population that would be appropriate for a SOC Type 1 report?

Answer options

Correct answer: C

Explanation

The correct answer is C, as potential clients do not have a direct relationship with the service organization and may not require the detailed information contained in a SOC Type 1 report. Current clients, auditors, and the service organization itself are appropriate audiences because they have a vested interest in understanding the service's controls and processes.