- The clause
- Detection and monitoring procedures that identify configuration changes introducing new vulnerabilities, and susceptibilities to newly discovered ones. Its point of focus addresses infrastructure and software vulnerability scans, on a periodic basis and after significant change.
- The output
- Per finding: the request that triggered it and the response that came back, the part of the exchange that demonstrates the defect marked, CVSS v4.0 with the vector printed, and the CWE.
- What your auditor does with it
- Evidence your service auditor can evaluate against CC7.1, and a record your remediation dates attach to, since the point of focus speaks to action taken on what gets identified.