Malicious software prevention and detection
Summary
The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software.
access controlmalware preventionvulnerability management
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
← Criterion CC6.7
Data transmission and movement controls
Criterion CC7.1 →
Vulnerability detection and monitoring
Track SOC 2 criterion CC6.8 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial