CC6.8
Prevents Unauthorized Software
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.
Points of focus
- Detects or prevents malicious software
- Controls introduction of unauthorized software
- Responds to malware or unauthorized software events
Implementation notes
AICPA CC6.8 expects controls that prevent or detect unauthorized or malicious software and that act when it appears. For SaaS, mandate MDM-enrolled, encrypted devices for any production or customer-data access, and deploy EDR (or equivalent platform controls) across the in-scope laptop and server fleet with measurable coverage. Pair endpoint controls with least privilege so engineers cannot silently install arbitrary packages on production hosts outside change-managed images. Publish a software installation / acceptable-use standard, block or review high-risk local admin, and route malware alerts into a documented response playbook with tickets. Evidence for Type II typically includes coverage reports, hardening baselines, and at least one closed alert showing detection-to-action. Contractors with production access must meet the same device bar or use managed jump environments.
Audit tip: Prove coverage percentages for EDR on in-scope endpoints and show a handled malware alert sample.
Evidence auditors typically request:
- EDR/AV deployment coverage reports
- Laptop hardening / MDM baselines
- Malware alert response tickets
- Software installation policy
Common gaps
- Unmanaged contractor devices with production access
- Servers without EDR agents
- No response playbook for malware alerts
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC6.8 | This control |
| ISO 27001 | A.8.7 | Protection against malware |
| HIPAA | 164.308(a)(5)(ii)(B) | Protection from malicious software |
| GDPR | Article 32(1) | Security of processing |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus