Files
odyssey/wiki/sources/2026-09-16-what-is-soc-2-compliance.md

4.2 KiB
Raw Blame History

tags, created, updated, sources, source_type, source_path, images, image_paths
tags created updated sources source_type source_path images image_paths
素材摘要
2026-09-16 2026-09-16
raw/notes/2026-09-16-what-is-soc-2-compliance.md
notes raw/notes/2026-09-16-what-is-soc-2-compliance.md 2

What is SOC 2 Compliance?(Fortinet 术语页)

SOC 2 是 AICPA 制定的自愿性合规标准,围绕五项信任服务原则(只有「安全」是必选)建立控制要求,最终产出 Type I 或 Type II 审计报告;它与面向财务的 SOC 1 是并列关系,而不是新旧版本。

基本信息

  • 来源类型:笔记(网页剪藏,Fortinet Cyber Glossary 术语页)
  • 原文位置:raw/notes/2026-09-16-what-is-soc-2-compliance.md
  • 原始链接:https://www.fortinet.com/resources/cyberglossary/soc-2-compliance
  • 素材日期:2026-09-16
  • 消化日期:2026-09-16
  • 图片:2 张引用(Fortinet logo、SOC 2 示意图),均为外部 CDN 链接,未下载到 raw/assets/;链接失效不影响正文理解
  • 敏感信息:入库前预扫无命中(无密钥、手机号、身份证号、密码)

核心观点

  1. SOC 2 是自愿标准,但事实上成了准入门槛。它由 AICPA 制定,是技术与云服务公司用来确保数据隐私合规的标准;虽然审计并非强制,但「many companies now expect SOC 2 compliance from vendors and providers」。
  2. 五项信任服务原则,只有「安全」是必选。Trust Services Criteria 包含安全、可用性、处理完整性、保密性、隐私五项,其余四项可按组织目标选择性纳入审计范围 —— 这直接决定了报告的形态各不相同。
  3. 报告分两类,区别在「时间段」而非「严格程度」。Type I 只评估某一时间点的控制是否被正确设计与实施,适合首次做审计的组织;Type II 在此基础上考察六个月的运行有效性。见 SOC 2 报告类型。
  4. SOC 1 与 SOC 2 是两条平行线。两者都出自 AICPA,但 SOC 1 报告的是保护客户财务报表的内控,面向财务机构;SOC 2 报告的是保护敏感客户数据的内控,面向非财务机构。见 SOC 1。
  5. 真正的驱动力是第三方风险。「over 80% of businesses」已向第三方开放全部云数据的访问权限;而第三方事故是近年最昂贵的企业数据泄露成因之一,单次平均成本近 150 万美元,而数据泄露的年均成本已接近 450 万美元 —— 这笔账构成了合规投入的商业理由。

关键概念

与其他素材的关联

知识库现有的两篇素材(wiki/sources/2026-09-14-n8n调用hermes-agents工作流架构、wiki/sources/2026-09-15-deepseek官方api接入codex)都是技术接入题材,与本文的合规/审计题材没有直接内容重叠,不能做事实层面的互证或反驳。

唯一可挂接的是视角层面的类比:现有素材讲的都是「与第三方交换数据或能力」(Codex 接第三方模型 API、Hermes API Server 对第三方开放端点),而本文提供的是这类第三方关系的合规审计视角。这条连接是跨素材推断,本文全文未提及任何 AI 工具。

原文精彩摘录

The five Trust Services Principles or Criteria outlined below can be included in a SOC 2 report, but only one is mandatory: security.

SOC 1 and SOC 2 both come from the AICPA, but they have different goals. SOC 2 is not necessarily an upgrade or newer version of SOC 1.

SOC 1 is for financial organizations, while SOC 2 is for nonfinancial entities.

Although third-party products and services increase an organization's ability to compete, they also increase the chances of sensitive data being breached or leaked.

相关页面