Definition
SOC 2 (System and Organisation Controls 2) is an audit standard developed by the American accounting body AICPA. It assesses a vendor's controls against five 'trustTrust - one of Tvimenning's core values and foundation for long-term customer relationships in the energy sector. service criteria': security, availability, processing integrity, confidentiality and privacy. The result is a SOC 2 report (Type I: the controls exist at a given point in time, or Type II: the controls have operated effectively over a period, typically 6-12 months) signed by an independent auditor. SOC 2 is not a certification in the same sense as ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. - it is an attestation report shared directly with customers under NDA, not a public mark.