68 lines
4.2 KiB
Markdown
68 lines
4.2 KiB
Markdown
---
|
||
tags: [素材摘要]
|
||
created: 2026-09-16
|
||
updated: 2026-09-16
|
||
sources: [raw/notes/2026-09-16-what-is-soc-2-compliance.md]
|
||
source_type: notes
|
||
source_path: raw/notes/2026-09-16-what-is-soc-2-compliance.md
|
||
images: 2
|
||
image_paths: []
|
||
---
|
||
|
||
# What is SOC 2 Compliance?(Fortinet 术语页)
|
||
|
||
> SOC 2 是 AICPA 制定的自愿性合规标准,围绕五项信任服务原则(只有「安全」是必选)建立控制要求,最终产出 Type I 或 Type II 审计报告;它与面向财务的 SOC 1 是并列关系,而不是新旧版本。
|
||
|
||
## 基本信息
|
||
|
||
- **来源类型**:笔记(网页剪藏,Fortinet Cyber Glossary 术语页)
|
||
- **原文位置**:raw/notes/2026-09-16-what-is-soc-2-compliance.md
|
||
- **原始链接**:https://www.fortinet.com/resources/cyberglossary/soc-2-compliance
|
||
- **素材日期**:2026-09-16
|
||
- **消化日期**:2026-09-16
|
||
- **图片**:2 张引用(Fortinet logo、SOC 2 示意图),均为外部 CDN 链接,未下载到 `raw/assets/`;链接失效不影响正文理解
|
||
- **敏感信息**:入库前预扫无命中(无密钥、手机号、身份证号、密码)
|
||
|
||
## 核心观点
|
||
|
||
1. **SOC 2 是自愿标准,但事实上成了准入门槛**。它由 [[AICPA]] 制定,是技术与云服务公司用来确保数据隐私合规的标准;虽然审计并非强制,但「many companies now expect SOC 2 compliance from vendors and providers」。
|
||
2. **五项信任服务原则,只有「安全」是必选**。[[Trust Services Criteria]] 包含安全、可用性、处理完整性、保密性、隐私五项,其余四项可按组织目标选择性纳入审计范围 —— 这直接决定了报告的形态各不相同。
|
||
3. **报告分两类,区别在「时间段」而非「严格程度」**。Type I 只评估某一时间点的控制是否被正确设计与实施,适合首次做审计的组织;Type II 在此基础上考察六个月的运行有效性。见 [[SOC 2 报告类型]]。
|
||
4. **SOC 1 与 SOC 2 是两条平行线**。两者都出自 AICPA,但 SOC 1 报告的是保护客户**财务报表**的内控,面向财务机构;SOC 2 报告的是保护**敏感客户数据**的内控,面向非财务机构。见 [[SOC 1]]。
|
||
5. **真正的驱动力是第三方风险**。「over 80% of businesses」已向第三方开放全部云数据的访问权限;而第三方事故是近年最昂贵的企业数据泄露成因之一,单次平均成本近 150 万美元,而数据泄露的年均成本已接近 450 万美元 —— 这笔账构成了合规投入的商业理由。
|
||
|
||
## 关键概念
|
||
|
||
- [[SOC 2]] — 本页主角,AICPA 的自愿性服务组织控制标准
|
||
- [[SOC 1]] — 面向财务报告内控的姊妹标准,与 SOC 2 成对理解
|
||
- [[Trust Services Criteria]] — SOC 2 的五项原则,决定审计范围
|
||
- [[SOC 2 报告类型]] — Type I / Type II 的分野
|
||
- [[AICPA]] — 标准的制定者
|
||
- [[合规与审计]] — 这些概念所属的知识领域
|
||
|
||
## 与其他素材的关联
|
||
|
||
知识库现有的两篇素材([[wiki/sources/2026-09-14-n8n调用hermes-agents工作流架构]]、[[wiki/sources/2026-09-15-deepseek官方api接入codex]])都是技术接入题材,与本文的合规/审计题材**没有直接内容重叠**,不能做事实层面的互证或反驳。
|
||
|
||
唯一可挂接的是视角层面的类比:现有素材讲的都是「与第三方交换数据或能力」(Codex 接第三方模型 API、Hermes API Server 对第三方开放端点),而本文提供的是这类第三方关系的**合规审计视角**。这条连接是跨素材推断,本文全文未提及任何 AI 工具。
|
||
<!-- confidence: INFERRED -->
|
||
|
||
## 原文精彩摘录
|
||
|
||
> The five Trust Services Principles or Criteria outlined below can be included in a SOC 2 report, but only one is mandatory: security.
|
||
|
||
> SOC 1 and SOC 2 both come from the AICPA, but they have different goals. SOC 2 is not necessarily an upgrade or newer version of SOC 1.
|
||
|
||
> SOC 1 is for financial organizations, while SOC 2 is for nonfinancial entities.
|
||
|
||
> Although third-party products and services increase an organization's ability to compete, they also increase the chances of sensitive data being breached or leaked.
|
||
|
||
## 相关页面
|
||
|
||
- [[合规与审计]]
|
||
- [[SOC 2]]
|
||
- [[SOC 1]]
|
||
- [[Trust Services Criteria]]
|
||
- [[SOC 2 报告类型]]
|
||
- [[AICPA]]
|