What does Trust Services categories mean on the CPA exam?
Trust Services categories. The five subject areas a SOC 2 can cover: security, availability, processing integrity, confidentiality and privacy. Security is in every engagement.
Defined against AICPA TSP Section 100.
Which CPA exam sections use Trust Services categories?
Trust Services categories appears in the ISC section of the CPA exam.
Related terms
- trust services criteria: The AICPA's control criteria for a SOC 2 engagement, in five categories: security, availability, processing integrity, confidentiality and privacy.
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- processing integrity: One of the trust services categories: system processing is complete, valid, accurate, timely and authorized.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.
- information-processing control: A control over processing in an IT application or a manual information process that directly addresses a risk to the integrity of information.
- PCI DSS: The Payment Card Industry Data Security Standard: contractual rules that anyone storing, processing or transmitting card data must follow.