A is corrent because SOC 3 reports are in essence based on having performed a SysTrust engagement for a service organization. B is incorrect because an SOC 1 engagement is based on an entity’s internal control over financial reporting more directly than upon SysTrust Principles. C is incorrect because there is no service entitled SOC OC. D is incorrect because there is no service entitled SOC SYS.
|