cc6.6-4-001

CC6.6 · D4 · f1

D4
Difficulty
4
Gaps
1
Red Herrings
57%
Avg Score

Task

You are auditing Prism Cloud's SOC 2 Type II compliance for control CC6.6 (System Boundary Protection). Review the provided evidence to assess whether Prism Cloud effectively protects its system boundaries through network segmentation, firewall rules, WAF deployment, and encryption of data in transit. Be thorough in cross-referencing evidence across documents — some apparent issues may have valid exceptions documented in the exception register.

Evidence

Findings

IDTypeSeverityFinding
F-001red_herringlowCross-VPC security group sg-0a1b2c3d4e5f60008 allows all traffic between staging and production
Security group sg-0a1b2c3d4e5f60008 (prod-data-sync-cross-vpc) contains rules sgr-021 and sgr-022 that allow all protocols and ports between the staging VPC (10.1.0.0/16) and the production VPC (10.0....
F-002gaphighWebhook receiver endpoint webhooks.prismcloud.io has no WAF protection
Security group sg-0a1b2c3d4e5f60011 (prod-webhook-receiver) accepts inbound HTTPS traffic on port 443 from 0.0.0.0/0 but has no WAF association (waf_association is null). The firewall rules export not...
F-003gaphighNotification service uses unencrypted HTTP for internal communication
The notification service (TLS-008 in the TLS config audit, sg-0a1b2c3d4e5f60006 in the firewall rules) uses unencrypted HTTP on port 8080 for internal communication from the application tier. The TLS ...
F-004gapmediumBatch processing security group allows outbound 0.0.0.0/0 on Elasticsearch port 9200
Security group sg-0a1b2c3d4e5f60012 (prod-batch-processing) contains outbound rule sgr-032 allowing TCP port 9200 to 0.0.0.0/0, described as 'Elasticsearch cluster access — legacy configuration pendin...
F-005gapmediumElasticsearch endpoint TLS-014 uses TLS 1.2 while handling customer PII
The Elasticsearch cluster endpoint (TLS-014, es.prod.prismcloud.local on port 9200) uses TLS 1.2 and is flagged as handling customer PII (search indices contain user profiles and activity data). The T...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic100%100%100%100%4/44
Opus 4.7Anthropic57%100%40%57%4/410
GPT-5.5OpenAI62%100%44%62%4/49
GPT-4.1OpenAI55%75%43%55%3/47
Haiku 4.5Anthropic25%75%15%25%3/420
GPT-4oOpenAI44%50%40%44%2/45