SOX Change Log Checker
Framework

SOC 2: what it asks of a production change

The Trust Services Criteria put change management in CC8.1 and the consideration of segregation in CC5.1; CC7.1 covers detecting configuration changes. The criteria are named by code and title here, not quoted.

Named, not quoted: the criteria text is not held in full here, so each criterion is named by code and title.

The findings it sits behind

3 clauses cited
FindingClause
No independent approvalSOC 2 CC8.1
Approved after it shippedSOC 2 CC8.1
Automated author, no human approvalSOC 2 CC8.1
Deployed their own changeSOC 2 CC5.1
One person, three rolesSOC 2 CC5.1
Emergency, no approval afterSOC 2 CC8.1
Deployment with no matching changeSOC 2 CC7.1
No ticket referenceSOC 2 CC8.1
Approver not on the listSOC 2 CC5.1
No test evidenceSOC 2 CC8.1

Every SOC 2 (Trust Services Criteria) clause the checker cites

Run the specimen Check your own change log