December 12, 2011

SOX and SOCs: Their Continued Inter-Play – Part 2

By Connie Spinelli, GRC Solutions

By now your company is likely in the Sarbanes-Oxley Section 404 mode. As internal auditors you are once again pondering what to do with what used to be SAS 70 reports, realizing that this year the issues are more complex. This article addresses the question: Do I request a SOC 1 Type 2 report or a SOC 2 Type 2 report from our organization’s data center or cloud service provider?