Your SOC 2 Type II audit is scheduled. Somewhere in the auditor's request list is a line that looks harmless:


"Provide evidence of your vulnerability management process, including identification, prioritization, and remediation of vulnerabilities during the observation period."


This maps to CC7.1 of the Trust Services Criteria — and it's one...