In a SOC 2® engagement, which Trust Services Criteria category is MANDATORY for every report?
Answer options:
A.
Security
B.
Availability
C.
Confidentiality
D.
Privacy
How to approach this question
Recall the Common Criteria rule.
Full Answer
A.Security✓ Correct
The Security category (also known as the Common Criteria) is the foundation of the Trust Services Criteria and is required for every SOC 2® engagement. Availability, Processing Integrity, Confidentiality, and Privacy are optional based on the service provided.