HostedScan

Vulnerability scanning for SOC 2

Run continuous scans across your entire attack surface, track remediation progress, and produce the vulnerability evidence your SOC 2 auditor needs. No manual effort required.

AICPA SOC logo

What It Is

SOC 2 Overview

System and Organization Controls (SOC) is a set of reports for auditing a business. SOC is maintained by the American Institute of Certified Public Accountants (AICPA). SOC 2 is the report for Trust Services Criteria.

The Solution

Does SOC 2 require vulnerability scanning?

Section CC7.1 of the Trust Services Criteria covers detection and monitoring for vulnerabilities.

Here is the full text of section CC7.1:

To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.

The following points of focus, specifically related to all engagements using the trust services criteria, highlight important characteristics relating to this criterion:

  • Uses Defined Configuration Standards — Management has defined configuration standards.
  • Monitors Infrastructure and Software — The entity monitors infrastructure and software for noncompliance with the standards, which could threaten the achievement of the entity objectives.
  • Implements Change-Detection Mechanisms — The IT system includes a change-detection mechanism (for example, file integrity monitoring tools) to alert personnel to unauthorized modifications of critical system files, configuration files, or content files.
  • Detects Unknown or Unauthorized Components — Procedures are in place to detect the introduction of unknown or unauthorized components.
  • Conducts Vulnerability Scans — The entity conducts vulnerability scans designed to identify potential vulnerabilities or misconfigurations on a periodic basis and after any significant change in the environment and takes action to remediate identified deficiencies on a timely basis.

Benefits of using HostedScan

How can HostedScan help with your SOC 2 goals?

Help protect your business and meet SOC 2 objectives with vulnerability scanning and management from HostedScan.

Scanners for every surface

Networks, servers, websites, and APIs covered by industry-leading vulnerability scanners in one platform.

Scheduled, automated scans

Run scans daily, weekly, or monthly. Get alerted the moment something new is found, without the manual effort.

Prioritized risk management

CVEs, OWASP Top 10, and exploitable weaknesses ranked by severity so your team knows exactly what to fix first.

Audit-ready reporting

Generate executive-ready vulnerability reports in seconds. Full coverage across all targets, prioritized by risk.

Our Customers

5,000+ MSPs and IT teams who move faster

BbAmericas
Porsche
ExpediaGroup
WeMakeApps
SibylSoft
Luminary
CoinMe
Appetize
WonderProxy
Median
TaxiCaller
Yamaha
UniversityOfOxford

Speed and power,
without the complexity

The world's leading vulnerability scanners, all in one platform.

Loading call to action