Skip to main content

Repository → 💼 SOC 2 → 💼 CC7 System Operations → 💼 CC7.1 To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.

💼 CC7.1-5 Conducts Vulnerability Scans

  • ID: /frameworks/soc-2/cc7/01/05

Description

The entity conducts vulnerability scans designed to identify potential vulnerabilities or misconfigurations on a periodic basis and after any significant change in the environment and takes action to remediate identified deficiencies on a timely basis.

Similar

  • Internal
    • ID: dec-c-719e7c41

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance