Change authorisation and testing
Summary
The entity authorises, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.
change managementsdlcrelease process
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
← Criterion CC7.5
Recovery from security incidents
Criterion CC9.1 →
Business disruption risk mitigation
Track SOC 2 criterion CC8.1 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial