Control Mapping Readerplace a control, see the map

SOC2-CC7.4 CC7.4 Responding to security incidents

SOC2-CC7.4 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.

The control as we hold it

CC7.4 Responding to security incidents. Identified security incidents are handled through a defined response programme that understands, contains, remediates and communicates them as appropriate. Points of focus: roles for designing, running and maintaining the programme are assigned, including outside help; incidents are contained, their ongoing effects mitigated and their threats ended by closing vulnerabilities and removing unauthorised access; operations and data are restored to an interim workable state; communication protocols reach affected parties; the nature and severity of each incident drive the response time frame and containment approach; vulnerabilities are remediated and the.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

HIPAA Security Rule

NIST SP 800-53 Rev 5

What an auditor commonly asks for

General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control