SOC Reports Explained: SOC 1, SOC 2 and SOC 3 for CISSP
What SOC 1, SOC 2 and SOC 3 cover, how Type 1 differs from Type 2, and how the CISSP exam approaches third party assurance and vendor risk.
Finding out whether the controls work rather than assuming they do: assessment, test and audit as three different strategies, the evidence each one produces, and the third-party reports an organisation relies on when it cannot look for itself.
The ISC2 CISSP exam outline lists these areas for Domain 6 and gives the domain a weighting of 12%. The wording below is a plain-English paraphrase; the outline itself is the source.
What SOC 1, SOC 2 and SOC 3 cover, how Type 1 differs from Type 2, and how the CISSP exam approaches third party assurance and vendor risk.
An assessment advises the organisation and can be self-performed. An audit gives an outsider a formal opinion, so independence is mandatory.
A formal, evidence-based evaluation of controls against a defined standard, performed by internal, external, or third-party auditors whose independence determines its credibility.
A structured evaluation of whether controls are implemented correctly, operating as intended, and producing the required outcome, evidenced by examining, interviewing and testing.
A systematic scan that identifies, quantifies, and ranks weaknesses across systems without exploiting them, trading depth for breadth and requiring validation of false positives.
An authorised simulated attack, run under written rules of engagement, that proves whether weaknesses are actually exploitable rather than merely listing them.
Testing that verifies what a system must not allow, inverting use cases into abuse scenarios to prove that invalid, malicious, or out-of-sequence actions are rejected.
Scripted, pre-built transactions run against live systems to verify functionality, availability, and response times proactively, catching failures before real users hit them.
A forward-looking metric that warns risk exposure is approaching an unacceptable level, triggering management action before loss occurs, unlike a KPI, which measures achieved performance.
Reading is half of it. Scenario questions in this domain tend to turn on the distinctions above, and the quickest way to find out which ones you hold is to answer some. The CISSP practice tests cover all eight domains with an explanation for every answer, and the free assessment gives you a baseline first.