SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC8.1: CC8.1 Managing changes to procedures, software, data and infrastructure

Every change to procedures, software, data or infrastructure is authorised, designed or acquired, configured, documented, tested, approved and implemented. Points of focus: changes are managed across the system life cycle; they are authorised before development, designed and developed, documented, tracked before implementation, configured, tested, approved and deployed; the effect on objectives is evaluated through the life cycle; changes needed to remediate incidents are identified and started; a configuration baseline is maintained for IT and control systems; emergency changes follow their own authorise-test-approve path; and confidential and personal information are protected during design, development, testing and change. The 2022 revision adds: segregation of responsibilities so one person cannot develop, test and deploy a change alone; testing of internally developed and acquired changes before production (unit, integration, regression, static and dynamic code analysis, quality assurance or automated testing); a process to identify, assess, test, approve and roll out patches on time; for availability, designing for resilience and testing it during development; and, for privacy, building privacy requirements into design and collecting and processing only the personal information the purpose needs.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 299 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 33 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 11.5.2 11.5.2 Change detection on critical files
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.3 6.2.3 Code review before release
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.5.6 6.5.6 Remove test data and accounts before production
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches
  • 6.4.3 6.4.3 Payment page script management
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change
  • 6.5.3 6.5.3 Separate pre-production from production
  • 6.5.4 6.5.4 Separate roles between production and pre-production

FedRAMP High · 29 controls

  • CA-9 Internal System Connections
  • CM-2 Baseline Configuration
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-3 Configuration Change Control
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • CM-3(4) Security and Privacy Representatives
  • CM-4 Impact Analyses
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • CM-6(1) Automated Management, Application, and Verification
  • CM-7(1) Periodic Review
  • CM-8(1) Updates During Installation and Removal
  • CM-9 Configuration Management Plan
  • CP-4(1) Coordinate with Related Plans
  • MA-2 Controlled Maintenance
  • MA-3 Maintenance Tools (MA-3)
  • RA-5(2) Update Vulnerabilities to be Scanned
  • SA-10 Developer Configuration Management
  • SA-11 Developer Testing and Evaluation
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • SA-22 Unsupported System Components (SA-22)
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles
  • SI-2 Flaw Remediation
  • SI-7 Software, Firmware, and Information Integrity
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

FedRAMP Moderate · 29 controls

  • CA-9 Internal System Connections
  • CM-2 Baseline Configuration
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-3 Configuration Change Control
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • CM-3(4) Security and Privacy Representatives
  • CM-4 Impact Analyses
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • CM-6(1) Automated Management, Application, and Verification
  • CM-7(1) Periodic Review
  • CM-8(1) Updates During Installation and Removal
  • CM-9 Configuration Management Plan
  • CP-4(1) Coordinate with Related Plans
  • MA-2 Controlled Maintenance
  • MA-3 Maintenance Tools (MA-3)
  • RA-5(2) Update Vulnerabilities to be Scanned
  • SA-10 Developer Configuration Management
  • SA-11 Developer Testing and Evaluation
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • SA-22 Unsupported System Components (SA-22)
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles
  • SI-2 Flaw Remediation
  • SI-7 Software, Firmware, and Information Integrity
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

NIST SP 800-53 Rev 5 · 28 controls

CIS Controls v8 · 17 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-12.4 Establish and Maintain Architecture Diagram(s)
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-16.8 Separate Production and Non-Production Systems
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

ISO 27001:2022 · 16 controls

  • 5.23 Information security for use of cloud services
  • 5.8 Information security in project management
  • 7.13 Equipment maintenance
  • 8.18 Use of privileged utility programs
  • 8.19 Installation of software on operational systems
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.29 Security testing in development and acceptance
  • 8.30 Outsourced development
  • 8.31 Separation of development, test and production environments
  • 8.32 Change management
  • 8.34 Protection of information systems during audit testing 
  • 8.4 Access to source code
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 27002:2022 · 16 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.8 Information security in project management
  • 7.13 Equipment maintenance
  • 8.15 Logging
  • 8.19 Installation of software on operational systems
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.31 Separation of development, test and production environments
  • 8.32 Change management
  • 8.34 Protection of information systems during audit testing
  • 8.4 Access to source code
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

CMMC 2.0 · 13 controls

NIST SP 800-218 · 13 controls

ISO/IEC 42001:2023 · 10 controls

  • 10.1 Continual improvement
  • 7.5 Documented information
  • 7.5.2 Creating and updating documented information
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 8.3 AI risk treatment
  • A.6 AI system life cycle
  • A.6.2.3 Documentation of AI system design and development
  • A.6.2.5 AI system deployment
  • A.6.2.6 AI system operation and monitoring
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

ISO 27701:2019 · 9 controls

  • 5.6 Operation
  • 5.6.1 Operational planning and control
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.2 Security in development and support processes
  • 6.9 Operations security
  • 6.9.1 Operational procedures and responsibilities
  • 6.9.5 Control of operational software
  • 6.9.7 Information systems audit considerations
  • 8.5.8 Change of subcontractor to process PII

C5 (Germany) · 8 controls

  • SEC01-BP06 Automate deployment of standard security controls
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP04 Conduct code reviews
  • SEC11-BP06 Deploy software programmatically
  • SEC11-BP07 Regularly assess security properties of the pipelines
  • AM-2 Use only approved services
  • ASBv3-DS-3 Secure DevOps infrastructure
  • ASBv3-GS-10 Define and implement DevOps security strategy
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • DS-6 Enforce security of workload throughout DevOps lifecycle

NIST SP 800-171 Rev 3 · 5 controls

  • CFTC-SS-32 Timely Advance Notice of Material Planned Changes
  • CFTC-SS-4 Systems Operations Category
  • CFTC-SS-5 Systems Development and Quality Assurance Category

ISO 22301:2019 · 3 controls

  • 6.3 Planning changes to the business continuity management system
  • 7.5.2 Creating and updating
  • 8.3.5 Implementation of solutions

DORA · 2 controls

EU AI Act · 2 controls

  • EUAI-Art.43 Conformity assessment
  • EUAI-Art.60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes

HIPAA Security Rule · 2 controls

  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process
  • SSAE18-CC3.4 CC3.4 - COSO Principle 9: Change Management
  • SSAE18-CC8.1 CC8.1 - Infrastructure and Software Change Management
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)

AICPA SOC 3 · 1 control

  • SOC3-CHANGE-MGT Change Management
  • ANSSI-HYG-34 Define an Update Policy for Information System Components

API 1164 · 1 control

  • API1164-23 Change management procedures
  • CPS230-9 Management of the Full Range of Operational Risks
  • Clause 10 Change and configuration management
  • AUCDR-IS-4 Formal vulnerability management program

BSI IT-Grundschutz · 1 control

  • BSI-24 Configuration change control
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

IEC 62443 · 1 control

  • IEC62443-23 Change management procedures
  • ISO-26262-8-8 Change management

ISO 27018:2019 · 1 control

  • 12.1.2 Change management

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO20000-06 Change management processes

ISO/IEC 27019:2024 · 1 control

  • ISO27019-23 Change management procedures

ITIL 4 · 1 control

  • ITIL4-06 Change management processes

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

NIST SP 1800-32 · 1 control

NIST SP 800-190 · 1 control

SASB Standards · 1 control

  • SASB-BMI-5 Physical Impacts of Climate Change

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC8.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 299 it maps to, and the evidence behind each claim, over MCP and REST.