CC7.1
Detection of Security Vulnerabilities
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.
Points of focus
- Uses defined configuration standards
- Monitors infrastructure and software for noncompliance with standards
- Implements change-detection mechanisms (for example, file integrity monitoring)
- Detects unknown or unauthorized components
- Conducts vulnerability scans periodically and after significant changes, and remediates deficiencies on a timely basis
Implementation notes
For SaaS SOC 2 Type II, treat CC7.1 as an operating vulnerability-management loop, not a one-off pen test. Define configuration standards for production images, Kubernetes/node baselines, and cloud accounts, then monitor for drift with CSPM, IaC policy checks, or file-integrity tooling on critical hosts. Run authenticated vulnerability scans (and container/image scanning where applicable) on a defined cadence and after material infrastructure changes. Track findings in tickets with severity-based SLAs, owners, and verification before close. Keep the scan population tied to your asset inventory so new accounts and clusters cannot silently fall out of scope. External penetration tests complement — they do not replace — continuous detection under AICPA CC7.1.
Audit tip: Show scan coverage of the in-scope population, severity SLAs, and a sample of critical findings from discovery to verified fix — not only the latest clean report.
Evidence auditors typically request:
- Vulnerability scanner configuration and authenticated scan reports for the period
- Configuration baselines / CIS or hardening standards for in-scope hosts and images
- File integrity monitoring or cloud config-drift alerts with response tickets
- Remediation SLAs and dated tickets closing high/critical findings
- Asset inventory tied to scan coverage
Common gaps
- Scans run but critical findings open past the stated SLA with no exception record
- Unauthenticated-only scans missing coverage of private VPC or container images
- No baseline or change-detection for production infrastructure-as-code / critical configs
- New cloud accounts or staging environments never added to the scan scope
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC7.1 | This control |
| ISO 27001 | A.8.8, A.8.9, A.8.29 | Vulnerability management, configuration baselines, and security testing |
| HIPAA | 164.308(a)(1)(ii)(A), 164.308(a)(8) | Risk analysis / evaluation and periodic evaluation |
| GDPR | Article 32(1)(d) | Regular testing and evaluation of security measures |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus