B is corrent because an SOC 1 engagement is based on an entity’s internal control over financial reporting more directly than upon SysTrust Principles. A is incorrect because no SOC 4 report is presented in the Professional Standards. C is incorrect because an SOC 2 report is on one or more of the SysTrust Principles. D is incorrect because an SOC 3 report is in essence a SysTrust report.
|