Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC3.4Identifies and assesses significant changesSOC 2Risk Assessment

Official Requirement

COSO Principle 9: The entity identifies and assesses changes that could significantly impact the system of internal control.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

When something significant changes, a new cloud provider, a major infrastructure migration, a new engineer with production access, a new regulation that applies to your business, you assess what that change means for your controls. Many companies have solid controls for their steady state but have gaps when the environment changes. This criterion asks whether your change management process includes a security impact assessment.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Security impact assessment as part of change management

Implementation steps

  1. Include a security impact question on the work order template for all infrastructure changes: 'Does this change affect any security controls? If yes, describe the impact and any new risks.'
  2. For significant changes (new server added to production, firewall rule changes, new third-party software installed), require a management sign-off that includes acknowledgement of security impact
  3. At the annual risk assessment, review the change log for the year and confirm significant changes were assessed

Tools / systems

Evidence artifacts

Evidence frequency: Per significant change; annual review confirmation