SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC7.1: CC7.1 Detecting configuration changes and new vulnerabilities

Detection and monitoring identify configuration changes that introduce vulnerabilities and exposure to newly discovered vulnerabilities. Points of focus: configuration standards are defined; infrastructure and software are monitored for departures from them; change-detection such as file integrity monitoring alerts staff to unauthorised changes to critical system, configuration or content files; unknown or unauthorised components are detected; and vulnerability scans run periodically and after significant change, with identified weaknesses acted on promptly enough to support objectives; the 2022 revision ties configuration standards expressly to hardening infrastructure and software.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 497 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 70 controls

  • 1.2.4 1.2.4 Accurate data-flow diagram for account data
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged
  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.2.1.6 10.2.1.6 Logs capture initialization and stopping of audit logs
  • 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects
  • 10.2.2 10.2.2 Required details recorded for each auditable event
  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 10.3.4 10.3.4 File integrity monitoring on audit logs
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.5.1 10.5.1 Keep logs 12 months, latest three months online
  • 10.6.1 10.6.1 System clocks synchronized with time-sync technology
  • 10.6.2 10.6.2 Systems configured to correct and consistent time
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.2.2 11.2.2 Inventory of authorized wireless access points
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 11.5.2 11.5.2 Change detection on critical files
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.4.2 6.4.2 Automated web attack detection and prevention
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.3.4 9.3.4 Visitor logs for facility and sensitive areas
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 9.4.5 9.4.5 Inventory logs of electronic media
  • 9.4.5.1 9.4.5.1 Annual inventories of electronic media
  • 9.5.1 9.5.1 Protection of POI devices from tampering
  • 9.5.1.2 9.5.1.2 Periodic inspection of POI device surfaces
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.4.3 6.4.3 Payment page script management

FedRAMP High · 69 controls

  • AC-17(1) Monitoring and Control
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-22 Publicly Accessible Content
  • AC-6(9) Log Use of Privileged Functions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7 Audit Record Reduction and Report Generation
  • AU-7(1) Automatic Processing
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8 Penetration Testing
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-6(1) Automated Reporting
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • MA-4 Nonlocal Maintenance
  • PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-10 Network Disconnect
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-5 Denial-of-Service Protection
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SC-7(4) External Telecommunications Services
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 69 controls

  • AC-17(1) Monitoring and Control
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-22 Publicly Accessible Content
  • AC-6(9) Log Use of Privileged Functions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7 Audit Record Reduction and Report Generation
  • AU-7(1) Automatic Processing
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8 Penetration Testing
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-6(1) Automated Reporting
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • MA-4 Nonlocal Maintenance
  • PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-10 Network Disconnect
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-5 Denial-of-Service Protection
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SC-7(4) External Telecommunications Services
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(7) Integration of Detection and Response

NIST SP 800-53 Rev 5 · 54 controls

CIS Controls v8 · 48 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-3.14 Log Sensitive Data Access
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.10 Retain Audit Logs
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.12 Collect Service Provider Logs
  • CIS-8.2 Collect Audit Logs
  • CIS-8.3 Ensure Adequate Audit Log Storage
  • CIS-8.4 Standardize Time Synchronization
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-8.6 Collect DNS Query Audit Logs
  • CIS-8.7 Collect URL Request Audit Logs
  • CIS-8.8 Collect Command-Line Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

CMMC 2.0 · 27 controls

ISO 27002:2022 · 16 controls

  • 5.24 Information security incident management planning and preparation
  • 5.28 Collection of evidence
  • 5.7 Threat intelligence
  • 6.8 Information security event reporting
  • 7.4 Physical security monitoring
  • 8.1 User endpoint devices
  • 8.12 Data leakage prevention
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization
  • 8.18 Use of privileged utility programs
  • 8.21 Security of network services
  • 8.34 Protection of information systems during audit testing
  • 8.7 Protection against malware
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 27001:2022 · 14 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.28 Collection of evidence
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.7 Threat intelligence
  • 6.8 Information security event reporting
  • 7.4 Physical security monitoring
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization 
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.27 Secure system architecture and engineering principles
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

HIPAA Security Rule · 13 controls

NIST SP 800-66 Rev 2 · 13 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

ISO 27701:2019 · 9 controls

  • 5.5 Support
  • 5.6 Operation
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.13 Information security incident management
  • 6.9 Operations security
  • 6.9.4 Logging and monitoring
  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management
  • 6.9.7 Information systems audit considerations

NIST SP 800-218 · 9 controls

  • ASBv3-NS-8 Detect and disable insecure services and protocols
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • ASBv3-PV-7 Conduct regular red team operations
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 7 controls

  • C5-OPS-16 Logging and Monitoring - Configuration
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • C5-PSS-11 Images for Virtual Machines and Containers

NIST SP 800-171 Rev 3 · 6 controls

  • ASD37-02 Patch applications (Essential)
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-19 Patch operating systems (Essential)

ISO/IEC 42001:2023 · 5 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.3.3 Reporting of concerns
  • A.6 AI system life cycle
  • A.6.2.6 AI system operation and monitoring
  • A.6.2.8 AI system recording of event logs
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

DORA · 4 controls

ACSC Essential Eight · 3 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)

NIST SP 800-161 Rev 1 · 3 controls

AICPA SOC 3 · 2 controls

  • SOC3-INCIDENT-MGT Incident Response
  • SOC3-VULN-MGT Vulnerability Management

NIS2 Directive · 2 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-172 · 2 controls

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

UK Cyber Essentials · 2 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.3 Critical and High Updates within 14 Days

APRA CPS 234 · 1 control

  • CPS234-30 Detection and Response Mechanisms
  • AUCDR-IS-4 Formal vulnerability management program

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

GDPR · 1 control

ISO 22301:2019 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC7.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 497 it maps to, and the evidence behind each claim, over MCP and REST.