control
CC6.8 — The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- framework
- soc2
- type
- preventive
- category
- technical
Details
- control_id
- CC6.8
- framework
- soc2
- group
- Common Criteria (Security)
- domains
- Secure Configuration & Change Management
- risk_count
- 2
- control_type
- preventive
- control_category
- technical
- automation
- automated
- key_control
- True
- requirement_status
- Not provided
- requirement_frequency
- Not provided
- source_url
- Not provided
- source_pages
- Not provided
Source
No record-specific source URL is provided.
Connections
- UC-CONFIG-05 — Permit only authorized software installation and use maps_to CC6.8 — The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- CC6.8 — The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives. belongs_to SOC 2 (TSC)