CAIQ v4 Control TVM-03 Extractive Review Standard

How to answer 'Do you perform automated software dependency scanning (SCA)?' on a CAIQ

Reviewer Guidance & Pitfalls

Name the SCA tool (e.g., Snyk, Dependabot, GitHub Security) and describe how high/critical CVEs in third-party libraries block CI/CD pull request merges.

Example Answer Passing Enterprise Audit

Compliant Response Template
Yes. Automated Software Composition Analysis (SCA) scans all dependencies on every pull request. Builds containing unresolved critical vulnerabilities are automatically blocked from deployment (SOC 2, CC7.1).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.