SOC 2

SOC 2 Trust Services Criteria coverage

How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to the SOC 2 Common Criteria (CC6 access, CC7 monitoring, CC8 change), the technical controls a SOC 2 review evaluates.

Technical evidence, not the full audit. LockList evidences the configuration side of these criteria. A SOC 2 examination also covers policies, risk assessment, and operating effectiveness over time. Use this to focus remediation; confirm scope with your auditor.
CriterionWhat LockList assesses
CC6.1Logical access controlsMFA for admins and all users, Security Defaults, Conditional Access coverage, named locations, guest/external access; 2-Step Verification (Google).
CC6.2Registration & authorizationAdmin role assignments and directory role membership; super admin inventory (Google).
CC6.3Access modification & removalPrivileged role assignments, suspended/dormant accounts, guest privileges, PIM (just in time) usage.
CC6.6Authentication boundariesMFA registration coverage and methods, legacy authentication blocking, 2-Step Verification coverage and admin enrollment.
CC6.7Restricting data movementSharePoint/OneDrive external sharing posture and external email auto forwarding.
CC6.8Unauthorized software / appsApp registrations holding high risk Microsoft Graph permissions.
CC7.1Configuration & vulnerabilityMicrosoft Secure Score and Defender / email security licensing posture; OS patch status and antivirus coverage across managed endpoints (NinjaOne).
CC7.2Security monitoringSign in and directory audit log accessibility (M365); login and admin audit logs (Google); activity log accessibility, open alerts, and stale / offline agents (NinjaOne).
CC7.3Evaluating security eventsRisky users (Identity Protection) and Conditional Access visibility in sign in logs.
CC8.1Change managementDirectory role inventory and configuration baseline used to track privileged changes.

Every finding in your LockList Report carries its SOC 2 criterion alongside ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 mappings. Run a free assessment →

GitHub

The GitHub connector assesses organisation level security controls mapped to these SOC 2 criteria.

CriterionWhat the GitHub connector assesses
CC6.1Logical access controlsOrg wide 2FA enforcement and SAML SSO configuration, ensuring all members authenticate with a second factor before accessing organisation resources.
CC6.2Registration & authorizationAdmin and member role inventory, flagging accounts with owner privileges beyond what is necessary.
CC6.3Access modification & removalDeploy key inventory and outside collaborator access review, identifying stale or overly permissive access to repositories.
CC6.8Unauthorized software / appsSecret scanning and push protection enablement, detecting committed secrets and blocking future leaks at push time.
CC8.1Change managementDefault branch protection rules (required reviews, status checks, force push restrictions), enforcing review gates on all production bound changes.