What does trust services criteria mean on the CPA exam?
Trust services criteria. The AICPA's control criteria for a SOC 2 engagement, in five categories: security, availability, processing integrity, confidentiality and privacy. Security applies to every SOC 2; the other four are chosen.
Defined against AICPA TSP Section 100.
Which CPA exam sections use trust services criteria?
Trust services criteria appears in the ISC section of the CPA exam.
Other names for trust services criteria
TSC
Related terms
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- Trust Services categories: The five subject areas a SOC 2 can cover: security, availability, processing integrity, confidentiality and privacy.
- processing integrity: One of the trust services categories: system processing is complete, valid, accurate, timely and authorized.
- control objectives: What a set of controls is supposed to achieve, stated so that it can be tested.
- SOC 3 report: A general use report on the same trust services criteria as a SOC 2, without the system description or the tests and results.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.