Frameworks / SOC 2 / SOC2-CC7.1 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC7.1: CC7.1 Detecting configuration changes and new vulnerabilities Detection and monitoring identify configuration changes that introduce vulnerabilities and exposure to newly discovered vulnerabilities. Points of focus: configuration standards are defined; infrastructure and software are monitored for departures from them; change-detection such as file integrity monitoring alerts staff to unauthorised changes to critical system, configuration or content files; unknown or unauthorised components are detected; and vulnerability scans run periodically and after significant change, with identified weaknesses acted on promptly enough to support objectives; the 2022 revision ties configuration standards expressly to hardening infrastructure and software.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 497 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.4 1.2.4 Accurate data-flow diagram for account data 1.2.5 1.2.5 Allowed services, protocols and ports justified 1.2.7 1.2.7 Six-monthly review of NSC configurations 1.5.1 1.5.1 Security controls on dual-connected devices 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data 10.2.1.2 10.2.1.2 Logs capture all administrative actions 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.2.1.6 10.2.1.6 Logs capture initialization and stopping of audit logs 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects 10.2.2 10.2.2 Required details recorded for each auditable event 10.3.2 10.3.2 Audit log files protected from modification 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage 10.3.4 10.3.4 File integrity monitoring on audit logs 10.4.1 10.4.1 Daily review of security-relevant logs 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review 10.4.2 10.4.2 Periodic review of all other system component logs 10.5.1 10.5.1 Keep logs 12 months, latest three months online 10.6.1 10.6.1 System clocks synchronized with time-sync technology 10.6.2 10.6.2 Systems configured to correct and consistent time 10.6.3 10.6.3 Time sync configuration and time data protected 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 10.7.2 10.7.2 Detect and alert on critical security control failures 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.2.2 11.2.2 Inventory of authorized wireless access points 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.3.2.1 11.3.2.1 External scans after significant change 11.4.2 11.4.2 Internal penetration testing annually and after change 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.5.2 11.5.2 Change detection on critical files 11.6.1 11.6.1 Payment page tamper detection 12.10.3 12.10.3 Incident response personnel available 24/7 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 12.5.1 12.5.1 Inventory of in-scope system components 12.6.1 12.6.1 Formal security awareness program 2.2.1 2.2.1 System configuration standards maintained 2.2.5 2.2.5 Insecure services, protocols or daemons secured 2.3.2 2.3.2 Wireless encryption keys changed on triggers 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.7.7 3.7.7 Prevent unauthorized substitution of keys 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates 5.3.4 5.3.4 Anti-malware audit logs enabled and retained 5.4.1 5.4.1 Mechanisms detect and protect against phishing 6.2.4 6.2.4 Engineering techniques against common software attacks 6.4.1 6.4.1 Public web application review or automated protection 6.4.2 6.4.2 Automated web attack detection and prevention 8.2.6 8.2.6 Inactive accounts removed within 90 days 8.2.7 8.2.7 Third-party remote access accounts controlled 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.3 9.2.3 Physical protection of network hardware and lines 9.3.4 9.3.4 Visitor logs for facility and sensitive areas 9.4.4 9.4.4 Management approval for media leaving facility 9.4.5 9.4.5 Inventory logs of electronic media 9.4.5.1 9.4.5.1 Annual inventories of electronic media 9.5.1 9.5.1 Protection of POI devices from tampering 9.5.1.2 9.5.1.2 Periodic inspection of POI device surfaces 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.4.3 6.4.3 Payment page script management AC-17(1) Monitoring and Control AC-2(2) Automated Temporary and Emergency Account Management AC-2(4) Automated Audit Actions AC-2(7) Privileged User Accounts AC-22 Publicly Accessible Content AC-6(9) Log Use of Privileged Functions AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-3(1) Additional Audit Information AU-4 Audit Log Storage Capacity AU-6 Audit Record Review, Analysis, and Reporting AU-6(1) Automated Process Integration AU-6(3) Correlate Audit Record Repositories AU-7 Audit Record Reduction and Report Generation AU-7(1) Automatic Processing AU-8 Time Stamps AU-9 Protection of Audit Information AU-9(4) Access by Subset of Privileged Users CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8 Penetration Testing CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CM-2 Baseline Configuration CM-3 Configuration Change Control CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-6 Configuration Settings CM-6(1) Automated Management, Application, and Verification CM-8(3) Automated Unauthorized Component Detection IR-1 Policy and Procedures IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-6(1) Automated Reporting IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) MA-3 Maintenance Tools (MA-3) MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1)) MA-4 Nonlocal Maintenance PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1)) PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) PE-6 Monitoring Physical Access PE-8 Visitor Access Records RA-5 Vulnerability Monitoring and Scanning RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11)) RA-5(2) Update Vulnerabilities to be Scanned RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SA-1 Policy and Procedures SA-2 Allocation of Resources SC-10 Network Disconnect SC-15 Collaborative Computing Devices and Applications SC-18 Mobile Code SC-5 Denial-of-Service Protection SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SI-11 Error Handling SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-4(4) Inbound and Outbound Communications Traffic SI-4(5) System-Generated Alerts SI-5 Security Alerts, Advisories, and Directives SI-7 Software, Firmware, and Information Integrity SI-7(7) Integration of Detection and Response AC-17(1) Monitoring and Control AC-2(2) Automated Temporary and Emergency Account Management AC-2(4) Automated Audit Actions AC-2(7) Privileged User Accounts AC-22 Publicly Accessible Content AC-6(9) Log Use of Privileged Functions AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-3(1) Additional Audit Information AU-4 Audit Log Storage Capacity AU-6 Audit Record Review, Analysis, and Reporting AU-6(1) Automated Process Integration AU-6(3) Correlate Audit Record Repositories AU-7 Audit Record Reduction and Report Generation AU-7(1) Automatic Processing AU-8 Time Stamps AU-9 Protection of Audit Information AU-9(4) Access by Subset of Privileged Users CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8 Penetration Testing CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CM-2 Baseline Configuration CM-3 Configuration Change Control CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-6 Configuration Settings CM-6(1) Automated Management, Application, and Verification CM-8(3) Automated Unauthorized Component Detection IR-1 Policy and Procedures IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-6(1) Automated Reporting IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) MA-3 Maintenance Tools (MA-3) MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1)) MA-4 Nonlocal Maintenance PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1)) PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) PE-6 Monitoring Physical Access PE-8 Visitor Access Records RA-5 Vulnerability Monitoring and Scanning RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11)) RA-5(2) Update Vulnerabilities to be Scanned RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SA-1 Policy and Procedures SA-2 Allocation of Resources SC-10 Network Disconnect SC-15 Collaborative Computing Devices and Applications SC-18 Mobile Code SC-5 Denial-of-Service Protection SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SI-11 Error Handling SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-4(4) Inbound and Outbound Communications Traffic SI-4(5) System-Generated Alerts SI-5 Security Alerts, Advisories, and Directives SI-7 Software, Firmware, and Information Integrity SI-7(7) Integration of Detection and Response NIST800-AC-23 AC-23 Data Mining Protection NIST800-AC-7 AC-7 Unsuccessful Logon Attempts NIST800-AC-9 AC-9 Previous Logon Notification NIST800-AU-1 AU-1 Policy and Procedures NIST800-AU-10 AU-10 Non-repudiation NIST800-AU-12 AU-12 Audit Record Generation NIST800-AU-14 AU-14 Session Audit NIST800-AU-16 AU-16 Cross-organizational Audit Logging NIST800-AU-2 AU-2 Event Logging NIST800-AU-3 AU-3 Content of Audit Records NIST800-AU-4 AU-4 Audit Log Storage Capacity NIST800-AU-5 AU-5 Response to Audit Logging Process Failures NIST800-AU-6 AU-6 Audit Record Review, Analysis, and Reporting NIST800-AU-7 AU-7 Audit Record Reduction and Report Generation NIST800-AU-8 AU-8 Time Stamps NIST800-AU-9 AU-9 Protection of Audit Information NIST800-CA-7 CA-7 Continuous Monitoring NIST800-CA-8 CA-8 Penetration Testing NIST800-CA-9 CA-9 Internal System Connections NIST800-CM-2 CM-2 Baseline Configuration NIST800-CM-6 CM-6 Configuration Settings NIST800-IR-3 IR-3 Incident Response Testing NIST800-IR-5 IR-5 Incident Monitoring NIST800-PE-10 PE-10 Emergency Shutoff NIST800-PE-20 PE-20 Asset Monitoring and Tracking NIST800-PM-12 PM-12 Insider Threat Program NIST800-PM-14 PM-14 Testing, Training, and Monitoring NIST800-PM-16 PM-16 Threat Awareness Program NIST800-PM-31 PM-31 Continuous Monitoring Strategy NIST800-RA-10 RA-10 Threat Hunting NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning NIST800-SC-15 SC-15 Collaborative Computing Devices and Applications NIST800-SC-17 SC-17 Public Key Infrastructure Certificates NIST800-SC-18 SC-18 Mobile Code NIST800-SC-38 SC-38 Operations Security NIST800-SC-43 SC-43 Usage Restrictions NIST800-SC-45 SC-45 System Time Synchronization NIST800-SI-1 SI-1 Policy and Procedures NIST800-SI-11 SI-11 Error Handling NIST800-SI-16 SI-16 Memory Protection NIST800-SI-2 SI-2 Flaw Remediation NIST800-SI-20 SI-20 Tainting NIST800-SI-4 SI-4 System Monitoring NIST800-SI-5 SI-5 Security Alerts, Advisories, and Directives NIST800-SI-6 SI-6 Security and Privacy Function Verification NIST800-SI-7 SI-7 Software, Firmware, and Information Integrity NIST800-SR-4 SR-4 Provenance NIST800-SR-9 SR-9 Tamper Resistance and Detection SP800-53-AU Audit and Accountability Family SP800-53-CA Assessment, Authorization, and Monitoring Family SP800-53-CM Configuration Management Family SP800-53-IR Incident Response Family SP800-53-MA Maintenance Family SP800-53-SI System and Information Integrity Family CIS-1.2 Address Unauthorized Assets CIS-1.3 Utilize an Active Discovery Tool CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory CIS-1.5 Use a Passive Asset Discovery Tool CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-13.1 Centralize Security Event Alerting CIS-13.11 Tune Security Event Alerting Thresholds CIS-13.2 Deploy a Host-Based Intrusion Detection Solution CIS-13.3 Deploy a Network Intrusion Detection Solution CIS-13.6 Collect Network Traffic Flow Logs CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.2 Perform Periodic External Penetration Tests CIS-18.4 Validate Security Measures CIS-18.5 Perform Periodic Internal Penetration Tests CIS-2.1 Establish and Maintain a Software Inventory CIS-2.2 Ensure Authorized Software is Currently Supported CIS-2.3 Address Unauthorized Software CIS-2.4 Utilize Automated Software Inventory Tools CIS-3.14 Log Sensitive Data Access CIS-4.1 Establish and Maintain a Secure Configuration Process CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-7.7 Remediate Detected Vulnerabilities CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.10 Retain Audit Logs CIS-8.11 Conduct Audit Log Reviews CIS-8.12 Collect Service Provider Logs CIS-8.2 Collect Audit Logs CIS-8.3 Ensure Adequate Audit Log Storage CIS-8.4 Standardize Time Synchronization CIS-8.5 Collect Detailed Audit Logs CIS-8.6 Collect DNS Query Audit Logs CIS-8.7 Collect URL Request Audit Logs CIS-8.8 Collect Command-Line Audit Logs CIS-8.9 Centralize Audit Logs CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions 5.24 Information security incident management planning and preparation 5.28 Collection of evidence 5.7 Threat intelligence 6.8 Information security event reporting 7.4 Physical security monitoring 8.1 User endpoint devices 8.12 Data leakage prevention 8.15 Logging 8.16 Monitoring activities 8.17 Clock synchronization 8.18 Use of privileged utility programs 8.21 Security of network services 8.34 Protection of information systems during audit testing 8.7 Protection against malware 8.8 Management of technical vulnerabilities 8.9 Configuration management 5.24 Information security incident management planning and preparation 5.28 Collection of evidence 5.36 Compliance with policies, rules and standards for information security 5.7 Threat intelligence 6.8 Information security event reporting 7.4 Physical security monitoring 8.15 Logging 8.16 Monitoring activities 8.17 Clock synchronization 8.20 Networks security 8.21 Security of network services 8.27 Secure system architecture and engineering principles 8.8 Management of technical vulnerabilities 8.9 Configuration management NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-PR.PS-01 Configuration management practices are established and applied NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved 5.5 Support 5.6 Operation 5.7.1 Monitoring, measurement, analysis and evaluation 6.13 Information security incident management 6.9 Operations security 6.9.4 Logging and monitoring 6.9.5 Control of operational software 6.9.6 Technical vulnerability management 6.9.7 Information systems audit considerations ASBv3-NS-8 Detect and disable insecure services and protocols ASBv3-PV-1 Define and establish secure configurations ASBv3-PV-3 Define and establish secure configurations for compute resources ASBv3-PV-4 Audit and enforce secure configurations for compute resources ASBv3-PV-7 Conduct regular red team operations PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments C5-OPS-16 Logging and Monitoring - Configuration C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests C5-OPS-22 Testing and Documentation of known Vulnerabilities C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening C5-PSS-02 Identification of Vulnerabilities of the Cloud Service C5-PSS-11 Images for Virtual Machines and Containers ASD37-02 Patch applications (Essential) ASD37-04 User application hardening (Essential) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) ASD37-19 Patch operating systems (Essential) 9.1 Monitoring, measurement, analysis and evaluation A.3.3 Reporting of concerns A.6 AI system life cycle A.6.2.6 AI system operation and monitoring A.6.2.8 AI system recording of event logs ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHOS-ML1 Patch Operating Systems (ML1) E8-PATCHOS-ML3 Patch Operating Systems (ML3) SOC3-INCIDENT-MGT Incident Response SOC3-VULN-MGT Vulnerability Management Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure Art.21.2.g Basic cyber hygiene practices and cybersecurity training 3.14.2e Monitor Organizational Systems with Specialized Capabilities 3.4.2e Automated Detection and Remediation of Unauthorized Software CE-SU.1 Software Licensed and Supported CE-SU.3 Critical and High Updates within 14 Days CPS234-30 Detection and Response Mechanisms AUCDR-IS-4 Formal vulnerability management program EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems 9.1 Monitoring, measurement, analysis and evaluation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC7.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 497 it maps to, and the evidence behind each claim, over MCP and REST.