SOX Change Log Checker
Clause text

SOC 2 (Trust Services Criteria): the clauses the checker cites

The 3 SOC 2 (Trust Services Criteria) clauses behind the findings, each with the evidence an auditor asks for where it is held.

Named, not quoted: the criteria text is not held in full here, so each criterion is named by code and title.

3 clauses

SOC 2 CC8.1 Change management processes are in place

Named, not quoted: the criteria text is not held in full here.

Evidence an auditor expects: The change management process covering infrastructure, data, software and procedures, including the emergency change route; Change records for the period showing design, development or acquisition, configuration, documentation, testing, approval and implementation; Evidence of segregation between those who develop, approve and implement changes; Testing evidence per change proportionate to its risk, including security testing where relevant; Evidence of rollback capability and of post implementation verification
Where it usually falls short: Emergency changes used routinely, with retrospective approval that is never withheld; Approval and implementation performed by the same person, so the approval is not independent
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks

Named, not quoted: the criteria text is not held in full here.

Evidence an auditor expects: Evidence control activities were selected in response to identified risks, traceable from the risk register to specific controls; The control matrix or equivalent, showing the mix of control types including preventive and detective and manual and automated; Evidence of consideration of the relevant business processes and of the level at which each control applies; Evidence of segregation of duties considered in control design, and compensating controls where segregation was not practicable; Evidence controls were assigned owners responsible for their performance
Where it usually falls short: Controls listed with no traceability to any risk, so the entity cannot show they mitigate anything identified; Detective controls absent, leaving no means to identify failure of the preventive ones
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC7.1 Detection and monitoring procedures for security events are in place

Named, not quoted: the criteria text is not held in full here.

Evidence an auditor expects: Defined configuration standards or baselines and evidence of monitoring for changes that introduce new vulnerabilities; Vulnerability scanning results for the period, including scope, frequency and whether scanning is authenticated; Evidence of monitoring for newly discovered vulnerabilities affecting the technologies in use; Records of deviations detected, the assessment of them and the remediation taken; Evidence the monitoring covers infrastructure, applications and cloud configuration
Where it usually falls short: Configuration monitored at build only, so drift introduced afterwards is never detected; Scanning performed quarterly against an environment that changes daily
Source: SOC 2 (Trust Services Criteria)