Share SOC Type 2 report with Clients

0

Being new to AWS, many of my clients are asking for me to share the latest AWS SOC Type 2 audit report as part of its vendor change, and what will be annual, security risk assessment. I need to know if I'm able to share the report with them as I was able to do that with my incumbent technical vendor.

3개 답변
2

Important NOTE - sharing the SOC 2 report requires us to follow a more formal process so that we know who has downloaded the report and how it's being used. The American Institute of Certified Public Accountants (AICPA) has rules that we must follow including the that SOC 1 or SOC 2 reports cannot be used as part of marketing/sales materials. Therefore it is critical that our customers access our certification/audit reports using AWS Artifacts so that we are properly recording these actions.

AWS
답변함 2년 전
0
수락된 답변

The terms and condition for the specific report are included on first page of the document you download from AWS Artifact. These T's & C's define when/if sharing is permissible. So I'd recommend that you download the current SOC 2 report and review the T's & C's against your situation.

AWS
Mark_Ev
답변함 2년 전
profile pictureAWS
전문가
검토됨 2년 전
0

AWS customers are able to access and download available versions of the SOC Reports (and others) through the AWS Artifact service in the management console.

AWS
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠