SOC2-CC7.4 CC7.4 Responding to security incidents
SOC2-CC7.4 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC7.4 Responding to security incidents. Identified security incidents are handled through a defined response programme that understands, contains, remediates and communicates them as appropriate. Points of focus: roles for designing, running and maintaining the programme are assigned, including outside help; incidents are contained, their ongoing effects mitigated and their threats ended by closing vulnerabilities and removing unauthorised access; operations and data are restored to an interim workable state; communication protocols reach affected parties; the nature and severity of each incident drive the response time frame and containment approach; vulnerabilities are remediated and the.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(1)(i) Security Management Process (Standard) (closest match)
- 164.308(a)(6)(i) Security Incident Procedures (Standard) (closest match)
- 164.308(a)(6)(ii) Response and Reporting (Required) (closest match)
- 164.312(a)(2)(ii) Emergency Access Procedure (Required) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AU-1 AU-1 Policy and Procedures (closest match)
- NIST800-AU-5 AU-5 Response to Audit Logging Process Failures (closest match)
- NIST800-IR-1 IR-1 Policy and Procedures (closest match)
- NIST800-IR-2 IR-2 Incident Response Training (closest match)
- NIST800-IR-3 IR-3 Incident Response Testing (closest match)
- NIST800-IR-4 IR-4 Incident Handling (closest match)
- NIST800-IR-5 IR-5 Incident Monitoring (closest match)
- NIST800-IR-6 IR-6 Incident Reporting (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records