SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
SOC2-CC7.3 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC7.3 Evaluating security events to identify incidents. Security events are evaluated to decide whether they could cause, or have caused, a failure to meet objectives, and if so action is taken to prevent or address the failure. Points of focus: incident response procedures exist and their effectiveness is evaluated periodically; people running the security programme are told of detected events and review them; procedures analyse incidents and their impact on the system; and in privacy engagements, events are assessed for unauthorised use or disclosure of personal information and legal non-compliance, and the personal information affected is identified. The 2022 revision adds, for.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(6)(i) Security Incident Procedures (Standard) (closest match)
- 164.308(a)(6)(ii) Response and Reporting (Required) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AU-1 AU-1 Policy and Procedures (closest match)
- NIST800-AU-6 AU-6 Audit Record Review, Analysis, and Reporting (closest match)
- NIST800-AU-7 AU-7 Audit Record Reduction and Report Generation (closest match)
- NIST800-AU-14 AU-14 Session Audit (closest match)
- NIST800-CA-7 CA-7 Continuous Monitoring (closest match)
- NIST800-IR-4 IR-4 Incident Handling (closest match)
- NIST800-IR-5 IR-5 Incident Monitoring (closest match)
- NIST800-IR-8 IR-8 Incident Response Plan (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records