| Trust Services Criteria | Control Name | Implementation Status | Evidence | Gaps / Notes | Owner |
|---|---|---|---|---|---|
CC1.1 |
COSO Principle 1 — Integrity & Ethics | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC2.1 |
Information for Internal Use | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC3.1 |
Risk Assessment | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC4.1 |
Design & Operate Monitoring Controls | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC5.1 |
Technology General Controls | PARTIALLY IMPLEMENTED | 2 lower-severity findings mapped to this control. | 2 open findings — see Gap Plan | [ORG TO COMPLETE: Control owner] |
CC6.1 |
Logical Access Security | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
CC6.2 |
Credentials & Secrets Management | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
CC6.3 |
Access Removal | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC6.6 |
System Boundaries | PARTIALLY IMPLEMENTED | 2 lower-severity findings mapped to this control. | 2 open findings — see Gap Plan | [ORG TO COMPLETE: Control owner] |
CC6.8 |
Software Security | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
CC7.1 |
Monitoring of Controls | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC8.1 |
Change Management | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
CC9.1 |
Risk Mitigation Procedures | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.