A growing payments SaaS firm keeps losing enterprise deals because prospective customers and their own auditors will not accept the firm's word that its controls work. The chief information security officer needs evidence that is produced by parties independent of the firm's own staff, so that a buyer's audit team can rely on it without re-running its own review. Which TWO activities most directly deliver that independent, externally produced assurance about the firm's security controls? Select TWO.
- ACommission a SOC 2 Type II report from a registered external audit firm that examines both the design and the operating effectiveness of the controls over a multi-month observation window. Correct
- BEngage an independent external penetration testing firm under a signed rules-of-engagement document to attempt real, chained exploitation of the production platform and report the verified findings. Correct
- CHave the firm's own internal audit team review the controls against an internal checklist and present the results to the firm's management committee each quarter.
- DAsk the engineering team to complete a control self-assessment questionnaire and have the head of engineering sign it off before sending it to prospects.
- EPublish the platform's availability dashboard showing monthly uptime percentages and incident response times for the hosted service to reassure prospects.
Why A is correct: A SOC 2 Type II is an attestation produced by an independent external auditor over a defined period, so a buyer's audit team can rely on it as third-party evidence rather than the firm's own assurances about its controls.
Why B is correct: An external penetration test is performed by a party independent of the firm and demonstrates control weaknesses through real exploitation, giving buyers third-party evidence of effectiveness that an internal claim cannot match.
Why C is wrong: Internal audit is genuinely useful and feels rigorous, but it is staffed and reported inside the firm, so an external buyer cannot treat its conclusions as the independent assurance the customers are demanding.
Why D is wrong: A self-assessment looks like evidence because it is documented and signed, but it is produced and attested by the very team being assessed, so it carries none of the independence a buyer's auditors require.
Why E is wrong: An uptime dashboard is tempting because it is objective public data, but it reports service availability rather than assessing security controls, so it answers a different question than the assurance the buyers are seeking.