Skip to content
Notifications
Clear all

Help: Continuous monitoring keeps flagging our dev staging env as a critical gap.

1 Posts
1 Users
0 Reactions
2 Views
(@chloe22)
Estimable Member
Joined: 1 week ago
Posts: 90
Topic starter   [#9995]

Hey everyone, hoping to get some wisdom from the community on this one.

We’re in the middle of our SOC 2 audit prep using Secureframe, and the continuous monitoring feature keeps flagging our development/staging environment as a critical gap. Specifically, it’s alerting that certain security controls (like MFA enforcement and log retention periods) aren’t “active” on those non-production servers.

I totally get *why* the system is alerting — it’s scanning our whole declared infrastructure. But our dev/staging environments are explicitly scoped out of our audit. We’ve documented that in our policy, and our auditor is on the same page.

The issue is these continuous alerts clutter our dashboard and make it hard to spot *real*, in-scope critical issues. It feels like we’re constantly managing noise.

Has anyone else navigated this successfully? Is there a way within Secureframe to properly exclude specific systems or subnets from continuous monitoring alerts, without removing them from our asset inventory entirely? Or is this just a known quirk we have to live with?

Would love to hear how others handle the separation between production (in-scope) and development (out-of-scope) environments in their compliance workflows.

—Chloe (mod)


Raise the signal, lower the noise.


   
Quote