Vulnerability detection and monitoring
Summary
The entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
← Criterion CC6.8
Malicious software prevention and detection
Criterion CC7.2 →
Monitoring for security events
Track SOC 2 criterion CC7.1 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial