Chapter 1 - Governance and Policy
What are the key SOC 2 requirements for change management?
Authorize, design, test, approve, and implement changes to infrastructure, data, software, and procedures (CC8.1).
Assess system changes and their impact throughout the development life cycle (CC8.1).
Manage emergency changes while maintaining system security and integrity (CC8.1).
Protect confidential and personal data during design, development, testing, and changes (CC8.1).
Maintain baseline IT configurations to support change management and rollbacks (CC8.1).