CAIQ v4
Control TVM-03
Extractive Review Standard
How to answer 'Do you perform automated software dependency scanning (SCA)?' on a CAIQ
Reviewer Guidance & Pitfalls
Name the SCA tool (e.g., Snyk, Dependabot, GitHub Security) and describe how high/critical CVEs in third-party libraries block CI/CD pull request merges.
Example Answer Passing Enterprise Audit
Compliant Response Template
Yes. Automated Software Composition Analysis (SCA) scans all dependencies on every pull request. Builds containing unresolved critical vulnerabilities are automatically blocked from deployment (SOC 2, CC7.1).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.