A cloud payroll vendor offers a SOC 2 Type I report dated 14 months ago to close a contract due Friday. HR wants to sign. What should the security manager do FIRST?
A. Require a current SOC 2 Type II before signing
B. Review the report's scope, period and exceptions against services used
C. Sign with a contractual right to audit clause
D. Commission an independent penetration test of the vendor
(Explain your answer for more points in the comments!)