Organisations are increasingly outsourcing systems, business processes and data processing to service providers in an effort to focus on core competencies, reduce costs, and more quickly deploy new application functionality.
With the retirement of the SAS 70 report in 2011, a new breed of Service Organisation Control (SOC) reports has been developed which more clearly address the specific assurance needs of the users of outsourced services.
This paper provides user organisations (customers) and service providers an overview of SOC 1 (ISAE 3402) and SOC2/SOC3. It also provides a guidance for effectively using these reports for increased assurance over outsourced services and controls.