Soc 3 (Service Organization Control 3)
A Service Organization Control 3 (Soc 3) report outlines information related to a service
organization’s internal controls for security, availability, processing integrity, confidentiality
or privacy. These
five areas are the focuses of the AICPA
Trust Services Principles and Criteria.
A Soc 3 reports on the same information as a Soc
2 report. The main difference between the two is that a Soc 3 is intended for a general
audience. These reports are shorter and do not include the same details as a Soc 2 report, which is
distributed to an informed audience of stakeholders. Due to their more general nature, Soc 3
reports can be shared openly and posted on a company’s website with a seal indicating their compliance.
Contributor(s): Alex DelVecchio
This was last updated in April 2012
Email Alerts
Register now to receive SearchCloudSecurity.com-related news, tips and more, delivered to your inbox.
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States.
Privacy
More News and Tutorials
-
What level of data privacy exists in the global cloud? Expert Francoise Gilbert compares international data privacy laws with the Patriot Act.
-
Marcus Ranum, security expert and Information Security magazine columnist, goes one-on-one with Randy Sabett, counsel at ZwillGen PLLC and formerly with the National Security Agency to discuss cloud SLAs.
-
A survey conducted by database security vendor GreenSQL found a high level of distrust in cloud services, despite the perception that transparency is increasing.