Home / Rules / The SPECIMEN organisation's own procedure / SSP-4 Accepted assurance
SSP-4 Accepted assurance
Accepted assurance for Tier 1: an ISO/IEC 27001 certificate whose scope covers the service, or a SOC 2 Type 2 report whose period ended within 12 months before the assessment date and whose system description covers the service we use. Complementary user entity controls (CUECs) in the report are mapped to our own controls before go-live.
The SPECIMEN organisation's own procedure (in the scenario inputs, supplier-security-procedure.md); no external clause decides this step.
Steps that cite it
- KC-01 S5 Assess the vendor's assurance report
Accepted citation forms are listed on the answer format page.