CC7.1: Detecting vulnerabilities and configuration changes
The company watches for new vulnerabilities and for unexpected changes to its infrastructure configuration, and fixes what it finds within defined timeframes.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC7 (System operations) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC7.1
The Policyseed crosswalk points CC7.1 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P11 Vulnerability and Patch Management Policy, sections 4 (Policy Statements) and 5 (Procedures). Owner: Engineering Lead.
- P12 Logging and Monitoring Policy, section 4 (Policy Statements). Owner: Engineering Lead.
- P20 Network and Infrastructure Security Policy, section 5 (Procedures). Owner: Engineering Lead.
Evidence examples for CC7.1
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Vulnerability scanner configuration and last quarter's scan reports
- Remediation tracker showing critical and high findings closed within the policy's SLA
- Cloud configuration monitoring alerts (for example AWS Config or GCP Security Command Center) export
- Infrastructure-as-code drift detection output or pull request history for the period
Related criteria in CC7 (System operations)
- CC7.2: Monitoring for anomalies
- CC7.3: Evaluating security events
- CC7.4: Responding to incidents
- CC7.5: Recovering from incidents
Previous: CC6.8 Malicious software. Next: CC7.2 Monitoring for anomalies. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.