Curious how others have handled marking dev/test resources as out of scope.
We're going through our first SOC 2 audit at Helmet Security. Vanta is detecting several development instances we use for integration testing and applying the same controls as our production environments.
The setup: one Azure account containing a test VM and a test Sentinel instance (Azure's equivalent of Splunk). No real workloads, no customer data: purely a test environment.
Is there a clean way to scope these out so they're not held to the same standards, without raising an auditor's eyebrow?