Skip to content
compliancebase
SOC 2CC7 — Detection of Security Vulnerabilities

CC7.1

Detection of Security Vulnerabilities

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.

Points of focus

  • Uses defined configuration standards
  • Monitors infrastructure and software for noncompliance with standards
  • Implements change-detection mechanisms (for example, file integrity monitoring)
  • Detects unknown or unauthorized components
  • Conducts vulnerability scans periodically and after significant changes, and remediates deficiencies on a timely basis

Implementation notes

For SaaS SOC 2 Type II, treat CC7.1 as an operating vulnerability-management loop, not a one-off pen test. Define configuration standards for production images, Kubernetes/node baselines, and cloud accounts, then monitor for drift with CSPM, IaC policy checks, or file-integrity tooling on critical hosts. Run authenticated vulnerability scans (and container/image scanning where applicable) on a defined cadence and after material infrastructure changes. Track findings in tickets with severity-based SLAs, owners, and verification before close. Keep the scan population tied to your asset inventory so new accounts and clusters cannot silently fall out of scope. External penetration tests complement — they do not replace — continuous detection under AICPA CC7.1.

Audit tip: Show scan coverage of the in-scope population, severity SLAs, and a sample of critical findings from discovery to verified fix — not only the latest clean report.

Evidence auditors typically request:

  • Vulnerability scanner configuration and authenticated scan reports for the period
  • Configuration baselines / CIS or hardening standards for in-scope hosts and images
  • File integrity monitoring or cloud config-drift alerts with response tickets
  • Remediation SLAs and dated tickets closing high/critical findings
  • Asset inventory tied to scan coverage

Common gaps

  • Scans run but critical findings open past the stated SLA with no exception record
  • Unauthenticated-only scans missing coverage of private VPC or container images
  • No baseline or change-detection for production infrastructure-as-code / critical configs
  • New cloud accounts or staging environments never added to the scan scope

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC7.1This control
ISO 27001A.8.8, A.8.9, A.8.29Vulnerability management, configuration baselines, and security testing
HIPAA164.308(a)(1)(ii)(A), 164.308(a)(8)Risk analysis / evaluation and periodic evaluation
GDPRArticle 32(1)(d)Regular testing and evaluation of security measures

Primary sources

Frequently Asked Questions

A pen test is strong complementary evidence, but CC7.1 centers on ongoing detection and monitoring for configuration-introduced and newly discovered vulnerabilities. Auditors typically expect periodic scanning (and remediation) across the observation window, not only one annual test report.

Monthly authenticated scans are common for SaaS; many programs scan continuously via agents or pipeline gates. Also rescan after significant environment changes. Document the cadence in policy and prove it operated during the Type II period.

Yes when those components support the in-scope system. Include image scanning, registry controls, and cloud configuration monitoring alongside classic host CVE scanning so the population matches your system description.

There is no universal AICPA SLA, but you must define severity-based timelines and show you met them or documented risk acceptance. Critical/high findings lingering without tickets or exceptions are a frequent exception.

Common mappings include A.8.8 (management of technical vulnerabilities) and A.8.9 (configuration management). Treat the crosswalk as related requirements, not identical wording or identical evidence packages.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above