During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?
Type II reports include testing of controls over a period.
Why this answer
A SOC 2 Type II report provides an independent assessment of controls over a period, confirming the vendor's control effectiveness.