cc6.3-3-001

CC6.3 · D3 · detection_and_precision

D3
Difficulty
5
Gaps
0
Red Herrings
87%
Avg Score

Task

You are conducting a SOC 2 Type II readiness assessment for ClearView Analytics covering Q4 2025. Review the data access authorization policy, the actual database grant configuration, and the data access request log. Cross-reference these documents to identify inconsistencies between policy and implementation. Assess compliance with CC6.3.

Evidence

Findings

IDTypeSeverityFinding
F-001gaphighdeveloper_debug role has full read-write access to all production tables
The policy (Section 3.1) requires CISO approval for write access to customer databases. The database grants show 'developer_debug' role has SELECT, INSERT, UPDATE, DELETE on ALL TABLES in clearview_pr...
F-002gaphighevan.smith has both etl_pipeline and developer_debug roles — segregation of duties violation
The role_memberships show evan.smith has both 'developer_debug' (full read-write to all tables) and 'etl_pipeline' (full read-write + TRUNCATE to all tables). This gives one user two overlapping privi...
F-003gaphighanalytics_readonly role has access to production database, not just analytics replica
Policy Section 3.4 states analysts access customer data through a 'read-only analytics replica' with PII masking. However, the database grants show 'analytics_readonly' has SELECT on ALL TABLES in cle...
F-004gapmediummarketing_integration accesses customer PII without Privacy Officer approval evidence
The marketing_integration role has SELECT access to customers, customer_events, and customer_profiles in production. DAR-404 shows Privacy Officer approved this. However, this is Confidential customer...
F-005gapmediumdeveloper_debug role granted via postgres superuser, not governed process
The database grants show developer_debug was granted by 'postgres' (the superuser account) on 2023-09-05, predating the current policy (effective August 2025). This suggests legacy access that was nev...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic100%100%42%59%5/512
Opus 4.7Anthropic100%100%42%59%5/512
GPT-5.5OpenAI100%100%50%67%5/510
GPT-4.1OpenAI80%80%50%62%4/58
Haiku 4.5Anthropic80%80%50%62%4/58
GPT-4oOpenAI60%60%50%55%3/56