{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.","details":{"automation":"automated","control_category":"technical","control_id":"CC7.1","control_type":"detective","domains":["Logging, Monitoring & Detection","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Vulnerability & Patch Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"id":"ctrl:soc2:CC7.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC7.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC7.1 — To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.","type":"control"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35f968a4c679ca801deafd807d768f88e3a721618bff69da66b19b70fea1c3bd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc7-1-a0583d17.json","sourceId":"ctrl:soc2:CC7.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d52f2055953fe737ee10babb032dda07f79f43ac7836cee7524f79c717db230","properties":{"control_id":"CC7.1","coverage":"partial","delta":"also requires monitoring susceptibility to newly discovered vulnerabilities","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-1-a0583d17.json","targetId":"ctrl:soc2:CC7.1","type":"maps_to"}],"schemaVersion":1}
