SOC2-CC7.5 CC7.5 Recovering from security incidents
SOC2-CC7.5 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC7.5 Recovering from security incidents. Recovery work after an identified security incident is identified, developed and carried out. Points of focus: the affected environment is returned to working order by rebuilding systems, updating software, patching and reconfiguring; the nature of the incident, recovery steps and prevention measures are communicated internally and externally as appropriate; the root cause is found; architecture or preventive and detective controls are changed to stop recurrence; lessons learned improve response and recovery procedures; and incident-recovery testing is performed periodically using scenarios weighted by how likely and how severe threats are,.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(6)(i) Security Incident Procedures (Standard) (closest match)
- 164.308(a)(7)(ii)(B) Disaster Recovery Plan (Required) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AU-6 AU-6 Audit Record Review, Analysis, and Reporting (closest match)
- NIST800-CP-10 CP-10 System Recovery and Reconstitution (closest match)
- NIST800-IR-2 IR-2 Incident Response Training (closest match)
- NIST800-IR-4 IR-4 Incident Handling (closest match)
- NIST800-IR-5 IR-5 Incident Monitoring (closest match)
- NIST800-IR-7 IR-7 Incident Response Assistance (closest match)
- NIST800-IR-8 IR-8 Incident Response Plan (closest match)
- NIST800-SI-2 SI-2 Flaw Remediation (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records