[Verse 1] Service organizations need to show their worth Trust Services Criteria light the way When clients store their data on your servers They need to know that you will keep it safe SOC 2 and 3 engagements tell the story Of controls that keep the business running right [Chorus] Security Availability Confidentiality Processing integrity and Privacy too S-A-C-P-P five criteria we see Trust Services framework guiding what we do Management assertions auditor testing SOC reports show the world what's true [Verse 2] SOC 2 Type One shows design at one point in time Are your controls designed effectively Type Two goes further tests throughout the year Operating effectiveness is the key Detailed reports for users with a need to know Management clients vendors who require proof [Chorus] Security Availability Confidentiality Processing integrity and Privacy too S-A-C-P-P five criteria we see Trust Services framework guiding what we do Management assertions auditor testing SOC reports show the world what's true [Bridge] SOC 3 is general use for everyone Summarized opinion freely shared around While SOC 2 stays restricted and detailed For those who need the comprehensive ground Both reports assess the same five criteria But audience determines what they show [Verse 3] Security protects from unauthorized access Availability means systems stay online Confidentiality keeps information private Processing integrity data stays refined Privacy criteria governs personal information Collection use retention and disposal [Chorus] Security Availability Confidentiality Processing integrity and Privacy too S-A-C-P-P five criteria we see Trust Services framework guiding what we do Management assertions auditor testing SOC reports show the world what's true [Outro] Service auditors following attestation standards CPA firms that specialize in trust Building confidence in service organizations SOC engagements earning client trust
← SOC 1 Engagements - Service Organizations | Internal Controls →