Files
odyssey/wiki/sources/2026-09-16-what-is-soc-2-compliance.md

68 lines
4.2 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
tags: [素材摘要]
created: 2026-09-16
updated: 2026-09-16
sources: [raw/notes/2026-09-16-what-is-soc-2-compliance.md]
source_type: notes
source_path: raw/notes/2026-09-16-what-is-soc-2-compliance.md
images: 2
image_paths: []
---
# What is SOC 2 Compliance?(Fortinet 术语页)
> SOC 2 是 AICPA 制定的自愿性合规标准,围绕五项信任服务原则(只有「安全」是必选)建立控制要求,最终产出 Type I 或 Type II 审计报告;它与面向财务的 SOC 1 是并列关系,而不是新旧版本。
## 基本信息
- **来源类型**:笔记(网页剪藏,Fortinet Cyber Glossary 术语页)
- **原文位置**:raw/notes/2026-09-16-what-is-soc-2-compliance.md
- **原始链接**:https://www.fortinet.com/resources/cyberglossary/soc-2-compliance
- **素材日期**:2026-09-16
- **消化日期**:2026-09-16
- **图片**:2 张引用(Fortinet logo、SOC 2 示意图),均为外部 CDN 链接,未下载到 `raw/assets/`;链接失效不影响正文理解
- **敏感信息**:入库前预扫无命中(无密钥、手机号、身份证号、密码)
## 核心观点
1. **SOC 2 是自愿标准,但事实上成了准入门槛**。它由 [[AICPA]] 制定,是技术与云服务公司用来确保数据隐私合规的标准;虽然审计并非强制,但「many companies now expect SOC 2 compliance from vendors and providers」。
2. **五项信任服务原则,只有「安全」是必选**。[[Trust Services Criteria]] 包含安全、可用性、处理完整性、保密性、隐私五项,其余四项可按组织目标选择性纳入审计范围 —— 这直接决定了报告的形态各不相同。
3. **报告分两类,区别在「时间段」而非「严格程度」**。Type I 只评估某一时间点的控制是否被正确设计与实施,适合首次做审计的组织;Type II 在此基础上考察六个月的运行有效性。见 [[SOC 2 报告类型]]。
4. **SOC 1 与 SOC 2 是两条平行线**。两者都出自 AICPA,但 SOC 1 报告的是保护客户**财务报表**的内控,面向财务机构;SOC 2 报告的是保护**敏感客户数据**的内控,面向非财务机构。见 [[SOC 1]]。
5. **真正的驱动力是第三方风险**。「over 80% of businesses」已向第三方开放全部云数据的访问权限;而第三方事故是近年最昂贵的企业数据泄露成因之一,单次平均成本近 150 万美元,而数据泄露的年均成本已接近 450 万美元 —— 这笔账构成了合规投入的商业理由。
## 关键概念
- [[SOC 2]] — 本页主角,AICPA 的自愿性服务组织控制标准
- [[SOC 1]] — 面向财务报告内控的姊妹标准,与 SOC 2 成对理解
- [[Trust Services Criteria]] — SOC 2 的五项原则,决定审计范围
- [[SOC 2 报告类型]] — Type I / Type II 的分野
- [[AICPA]] — 标准的制定者
- [[合规与审计]] — 这些概念所属的知识领域
## 与其他素材的关联
知识库现有的两篇素材([[wiki/sources/2026-09-14-n8n调用hermes-agents工作流架构]]、[[wiki/sources/2026-09-15-deepseek官方api接入codex]])都是技术接入题材,与本文的合规/审计题材**没有直接内容重叠**,不能做事实层面的互证或反驳。
唯一可挂接的是视角层面的类比:现有素材讲的都是「与第三方交换数据或能力」(Codex 接第三方模型 API、Hermes API Server 对第三方开放端点),而本文提供的是这类第三方关系的**合规审计视角**。这条连接是跨素材推断,本文全文未提及任何 AI 工具。
<!-- confidence: INFERRED -->
## 原文精彩摘录
> The five Trust Services Principles or Criteria outlined below can be included in a SOC 2 report, but only one is mandatory: security.
> SOC 1 and SOC 2 both come from the AICPA, but they have different goals. SOC 2 is not necessarily an upgrade or newer version of SOC 1.
> SOC 1 is for financial organizations, while SOC 2 is for nonfinancial entities.
> Although third-party products and services increase an organization's ability to compete, they also increase the chances of sensitive data being breached or leaked.
## 相关页面
- [[合规与审计]]
- [[SOC 2]]
- [[SOC 1]]
- [[Trust Services Criteria]]
- [[SOC 2 报告类型]]
- [[AICPA]]