Skip to content
compliancebase
SOC 2CC6 — Prevents Unauthorized Software

CC6.8

Prevents Unauthorized Software

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.

Points of focus

  • Detects or prevents malicious software
  • Controls introduction of unauthorized software
  • Responds to malware or unauthorized software events

Implementation notes

AICPA CC6.8 expects controls that prevent or detect unauthorized or malicious software and that act when it appears. For SaaS, mandate MDM-enrolled, encrypted devices for any production or customer-data access, and deploy EDR (or equivalent platform controls) across the in-scope laptop and server fleet with measurable coverage. Pair endpoint controls with least privilege so engineers cannot silently install arbitrary packages on production hosts outside change-managed images. Publish a software installation / acceptable-use standard, block or review high-risk local admin, and route malware alerts into a documented response playbook with tickets. Evidence for Type II typically includes coverage reports, hardening baselines, and at least one closed alert showing detection-to-action. Contractors with production access must meet the same device bar or use managed jump environments.

Audit tip: Prove coverage percentages for EDR on in-scope endpoints and show a handled malware alert sample.

Evidence auditors typically request:

  • EDR/AV deployment coverage reports
  • Laptop hardening / MDM baselines
  • Malware alert response tickets
  • Software installation policy

Common gaps

  • Unmanaged contractor devices with production access
  • Servers without EDR agents
  • No response playbook for malware alerts

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.8This control
ISO 27001A.8.7Protection against malware
HIPAA164.308(a)(5)(ii)(B)Protection from malicious software
GDPRArticle 32(1)Security of processing

Primary sources

Frequently Asked Questions

Signature-only AV is rarely sufficient for modern SaaS programs. Auditors typically expect EDR or equivalent with alerting, investigation, and response — plus policy for unauthorized software — not a silent desktop AV install with no coverage metrics or tickets.

In-scope compute should meet your malware and unauthorized-software control design. That may be host agents, container/image scanning and immutable infrastructure, or cloud workload protection — document the design and prove coverage for the population auditors will sample.

CC6.8 reduces introduction of unauthorized or malicious software on endpoints and hosts; CC8.1 governs authorized changes to production systems. Golden images, pipeline-only deploys, and blocked ad-hoc package installs on servers connect the two criteria in practice.

Treat high-risk client software — including browser extensions that can read corporate data — as part of acceptable use and hardening standards. MDM or browser management that limits extension installs is strong evidence when customer or production data is reachable from the endpoint.

Only with strong MDM, containerization, or equivalent isolation, and a clear rule that unmanaged devices cannot reach production. Many teams simply require company-managed devices for privileged access — which is easier to evidence for Type II sampling.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above