SOC 2
SOC 2 Trust Services Criteria coverage
How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to the SOC 2 Common Criteria (CC6 access, CC7 monitoring, CC8 change), the technical controls a SOC 2 review evaluates.
Technical evidence, not the full audit. LockList evidences the configuration side of these criteria. A SOC 2 examination also covers policies, risk assessment, and operating effectiveness over time. Use this to focus remediation; confirm scope with your auditor.
| Criterion | What LockList assesses |
|---|---|
| CC6.1Logical access controls | MFA for admins and all users, Security Defaults, Conditional Access coverage, named locations, guest/external access; 2-Step Verification (Google). |
| CC6.2Registration & authorization | Admin role assignments and directory role membership; super admin inventory (Google). |
| CC6.3Access modification & removal | Privileged role assignments, suspended/dormant accounts, guest privileges, PIM (just in time) usage. |
| CC6.6Authentication boundaries | MFA registration coverage and methods, legacy authentication blocking, 2-Step Verification coverage and admin enrollment. |
| CC6.7Restricting data movement | SharePoint/OneDrive external sharing posture and external email auto forwarding. |
| CC6.8Unauthorized software / apps | App registrations holding high risk Microsoft Graph permissions. |
| CC7.1Configuration & vulnerability | Microsoft Secure Score and Defender / email security licensing posture; OS patch status and antivirus coverage across managed endpoints (NinjaOne). |
| CC7.2Security monitoring | Sign in and directory audit log accessibility (M365); login and admin audit logs (Google); activity log accessibility, open alerts, and stale / offline agents (NinjaOne). |
| CC7.3Evaluating security events | Risky users (Identity Protection) and Conditional Access visibility in sign in logs. |
| CC8.1Change management | Directory role inventory and configuration baseline used to track privileged changes. |
Every finding in your LockList Report carries its SOC 2 criterion alongside ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 mappings. Run a free assessment →
GitHub
The GitHub connector assesses organisation level security controls mapped to these SOC 2 criteria.
| Criterion | What the GitHub connector assesses |
|---|---|
| CC6.1Logical access controls | Org wide 2FA enforcement and SAML SSO configuration, ensuring all members authenticate with a second factor before accessing organisation resources. |
| CC6.2Registration & authorization | Admin and member role inventory, flagging accounts with owner privileges beyond what is necessary. |
| CC6.3Access modification & removal | Deploy key inventory and outside collaborator access review, identifying stale or overly permissive access to repositories. |
| CC6.8Unauthorized software / apps | Secret scanning and push protection enablement, detecting committed secrets and blocking future leaks at push time. |
| CC8.1Change management | Default branch protection rules (required reviews, status checks, force push restrictions), enforcing review gates on all production bound changes. |