SOX Change Log Checker
Change type

Configuration changes: what the auditor reads in them

A feature flag or a parameter change can alter what a financial system does without a code change. When these go through a separate console, they often carry no ticket and no approval on the export.

How the checker recognises them

Read from the title: config, feature flag, setting, parameter, toggle, threshold, rate and the like.

Findings they raise most often

The clauses that speak to them

3 clauses
COBIT BAI10.03 Maintain and control configuration items
The clause text

An up-to-date repository of configuration items is maintained by populating all configuration changes: all changes to CIs are regularly identified, proposed changes are reviewed against the baseline for completeness and accuracy, configuration details are updated for approved changes, and changes to baselines are created, reviewed and formally agreed whenever needed.

Evidence an auditor expects: Configuration updates tied to approved changes; baseline change approvals
Where it usually falls short: Repository that describes the environment as it was months ago
Source: COBIT 2019
SOC 2 CC7.1 Detection and monitoring procedures for security events are in place

Named, not quoted: the criteria text is not held in full here.

Evidence an auditor expects: Defined configuration standards or baselines and evidence of monitoring for changes that introduce new vulnerabilities; Vulnerability scanning results for the period, including scope, frequency and whether scanning is authenticated; Evidence of monitoring for newly discovered vulnerabilities affecting the technologies in use; Records of deviations detected, the assessment of them and the remediation taken; Evidence the monitoring covers infrastructure, applications and cloud configuration
Where it usually falls short: Configuration monitored at build only, so drift introduced afterwards is never detected; Scanning performed quarterly against an environment that changes daily
Source: SOC 2 (Trust Services Criteria)
ISO 27001 8.9 Configuration management
The clause text

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

Evidence an auditor expects: Baseline configurations; Change control records; Configuration audit reports; Secure hardening guidelines; Deviation approvals
Where it usually falls short: Outdated baselines; Missing change approvals
Source: ISO/IEC 27001:2022

Other change types

Run the specimen Check your own change log