cc8.1-1-001

CC8.1 · D1 · detection_only

D1
Difficulty
3
Gaps
0
Red Herrings
100%
Avg Score

Task

Review the change management policy for Orion Health and assess whether it adequately addresses SOC 2 CC8.1 requirements. Identify any gaps or missing elements.

Evidence

Findings

IDTypeSeverityFinding
F-001gaphighNo segregation of duties in change deployment
Section 4.3 states 'Changes are deployed by the requesting engineer.' The same person who requests a change also deploys it. CC8.1 requires segregation of duties — the person who develops/requests a c...
F-002gaphighNo testing requirement before production deployment
The policy mentions CI/CD pipeline goes from staging to production but does not require testing in staging, test results sign-off, or QA validation before promotion to production. CC8.1 explicitly req...
F-003gapmediumEmergency change process lacks controls
Emergency changes require only verbal approval and a retroactive Jira ticket. No requirement for post-implementation security review, no time limit for creating the retroactive ticket, and no verifica...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic100%100%38%55%3/38
Opus 4.7Anthropic100%100%23%38%3/313
GPT-5.5OpenAI100%100%20%33%3/315
GPT-4.1OpenAI100%100%38%55%3/38
Haiku 4.5Anthropic100%100%38%55%3/38
GPT-4oOpenAI100%100%60%75%3/35