Organisations are increasingly outsourcing systems, business processes, and data processing to service providers in an effort to focus on core competencies, reduce costs, and more quickly deploy new application functionality. As a result, organisations are updating their processes for monitoring their outsourced vendor relationships and managing the risks associated with outsourcing.
This paper provides user organisations (customers) and service providers an overview of SOC2/SOC3 and guidance for the application of SOC2/SOC3 reporting. In addition, it provides a contrast between the scopes of SOC2/SOC3 and SOC1 reports.