712-50 exam dumps

712-50 practice question 54 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 54

Single answerUnderstand the compliance auditing and certification programs

A global SaaS company is preparing to enter the enterprise healthcare market in the United States and Europe. Several prospective customers have asked for evidence that the company has undergone independent assurance over the design and operating effectiveness of controls relevant to security, availability, and confidentiality. The board wants a program that is broadly recognized, can be shared under NDA with customers, and is more appropriate for customer assurance than a management-system certification alone. As the CISO, which option should you recommend first?

  1. A

    Pursue ISO/IEC 27001 certification only, because the certificate by itself provides detailed assurance to customers on control effectiveness

  2. B

    Obtain a SOC 2 Type II report covering the trust services criteria most relevant to the service, because it provides independent attestation on control design and operating effectiveness over a period of time

  3. C

    Complete a PCI DSS self-assessment questionnaire, because it is the most broadly accepted proof of overall information security maturity for healthcare and European enterprise customers

  4. D

    Request an internal audit report mapped to HIPAA and GDPR, because customer assurance requirements are typically satisfied by the organization's own audit function

Show answer and explanation

Correct answer: B

Explanation

The best answer is to obtain a SOC 2 Type II report. The scenario distinguishes between compliance, certification, and attestation in a practical procurement context. ISO/IEC 27001 is a certification against an ISMS standard and demonstrates that an accredited certification body has audited the management system against the standard's requirements. However, customers often want an attestation report that addresses specific controls relevant to a service and whether those controls operated effectively over time. SOC 2 Type II, based on the AICPA Trust Services Criteria, is commonly used for this purpose in SaaS and cloud environments and is typically shared with customers under NDA.

This reflects an important CCISO distinction: compliance auditing and certification programs serve different purposes. Certifications such as ISO/IEC 27001 validate conformance of a management system to a standard. Attestation reports such as SOC 2 evaluate and report on controls for stakeholder reliance. Regulatory mappings such as HIPAA and GDPR help demonstrate legal and compliance alignment, but they are not, by themselves, equivalent to a broadly recognized independent assurance report. Similarly, PCI DSS is highly relevant when processing payment card data, but it is not a general-purpose assurance mechanism for all customer trust requirements.

Relevant references and best practices include the AICPA guidance for SOC 2 examinations and the ISO/IEC 27001 standard for ISMS certification. From a governance perspective, the CISO should align the assurance program to stakeholder needs: certifications for management-system credibility, attestation reports for customer assurance, and targeted compliance assessments for regulatory or industry-specific obligations.

  • A. Incorrect.

    Incorrect. ISO/IEC 27001 certification is a recognized certification of an information security management system (ISMS), and it can be valuable as part of a broader assurance strategy. However, a certificate alone does not typically provide customers with the same level of detailed assurance about control design and operating effectiveness for a specific service that a SOC 2 Type II report does. A common misconception is to treat ISO 27001 certification as a direct substitute for a customer-facing attestation report. In practice, many customers view ISO 27001 as evidence of a certified management system, while SOC 2 Type II is more directly used for third-party assurance.

  • B. Correct.

    Correct. A SOC 2 Type II report, performed under the AICPA attestation framework, is specifically designed to provide independent assurance to user entities and stakeholders regarding controls relevant to the Trust Services Criteria, such as security, availability, and confidentiality. Type II reports address not only whether controls are suitably designed, but also whether they operated effectively over a defined review period. This aligns well with the scenario's requirement for customer-shareable evidence under NDA and independent assurance beyond a management-system certification alone.

  • C. Incorrect.

    Incorrect. PCI DSS is a payment card industry standard focused on protecting cardholder data and the cardholder data environment. Even when relevant, a self-assessment questionnaire is limited in scope and is not a broadly accepted substitute for enterprise-wide assurance regarding security, availability, and confidentiality for SaaS services. Choosing this option reflects the misconception that a domain-specific compliance exercise can serve as a universal assurance artifact for unrelated customer requirements, such as healthcare or general European enterprise procurement.

  • D. Incorrect.

    Incorrect. Internal audit reports can be useful for governance and internal oversight, but they generally do not satisfy external customer demands for independent third-party assurance. In this scenario, prospective customers are explicitly asking for evidence of independent assurance. While mapping controls to HIPAA and GDPR may support compliance efforts, internal audit lacks the external attestation value and market recognition typically expected in vendor due diligence programs.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam