Does SOC 2 Type II Require Penetration Testing?

preview_player
Показать описание
Developed by the AICPA, SOC 2 is specifically designed for technology service providers that store client data in the cloud. SOC 2 applies to nearly every SaaS (Software-as-a-Service) company, as well as any company that uses the cloud to store client information.

We recommend penetration testing once a quarter as part of SOC 2 compliance. Penetration testing is used to test control effectiveness in SOC 2 Type II audits.

Learn more about SOC 2 Type II Penetration Testing:

Alpine Security is now a wholly owned member of the CISO Global family of companies.

#soc2 #socaudit #penetrationtesting
Рекомендации по теме
join shbcf.ru