CC8.1: Change management
Changes to software and infrastructure are authorized, developed and tested in a controlled way, reviewed by someone other than the author, approved, and deployed with a way to roll back.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC8 (Change management) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC8.1
The Policyseed crosswalk points CC8.1 at 2 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P09 Change Management Policy, sections 4 (Policy Statements) and 5 (Procedures). Owner: Engineering Lead.
- P10 Secure Software Development Policy, section 4 (Policy Statements). Owner: Engineering Lead.
Evidence examples for CC8.1
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Branch protection settings export requiring pull request review and passing checks before merge
- Sample of merged pull requests from the period showing reviewer approval and CI status
- CI/CD pipeline configuration file showing automated tests and the production deploy step
- Emergency change record showing after-the-fact review, if any occurred
Related criteria in CC8 (Change management)
CC8.1 is the only criterion in the CC8 series. Use the neighbours below to keep reading through the crosswalk.
Previous: CC7.5 Recovering from incidents. Next: CC9.1 Mitigating business disruption risk. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.