SOC 2
CC - Common Criteria (Security)

SOC 2 CC7.1: Detection and monitoring procedures for security events are in place

To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 612 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 70 controls

  • 1.2.4 Data flow diagram of account data
  • 1.2.5 Services, protocols, ports inventoried and justified
  • 1.2.7 NSC rule sets reviewed every six months
  • 1.5.1 Security controls on dual-connected computing devices
  • 10.1.2 Requirement 10 roles and responsibilities documented and assigned
  • 10.2.1 Audit logs enabled on system components
  • 10.2.1.1 Log all user access to CHD
  • 10.2.1.2 Log all admin actions
  • 10.2.1.3 Log access to audit logs
  • 10.2.1.4 Log invalid logical access attempts
  • 10.2.1.5 Log changes to identification and authentication
  • 10.2.1.6 Log initialization, stopping, or pausing of logs
  • 10.2.1.7 Log creation and deletion of system level objects
  • 10.2.2 Audit log content
  • 10.3.2 Logs protected from modification
  • 10.3.3 Logs backed up to central server
  • 10.3.4 File integrity or change detection on logs
  • 10.4.1 Daily log review for critical systems
  • 10.4.1.1 Automated mechanisms for log review
  • 10.4.2 Periodic review of other system component logs
  • 10.5.1 Audit log retention 12 months
  • 10.6.1 Time synchronization in use
  • 10.6.2 Time settings consistent and accurate
  • 10.6.3 Time settings protected
  • 10.7.1 Critical security control failure detection (SP)
  • 10.7.2 Critical security control failure detection (all entities)
  • 11.2.1 Wireless AP detection
  • 11.2.2 Authorized wireless AP inventory
  • 11.3.1 Internal vulnerability scans quarterly
  • 11.3.1.1 Address non-high vulnerabilities per TRA
  • 11.3.1.2 Authenticated internal scans
  • 11.3.1.3 Internal scans after significant changes
  • 11.3.2 External vulnerability scans quarterly by ASV
  • 11.3.2.1 External scans after significant change
  • 11.4.2 Internal penetration testing annually
  • 11.5.1 IDS/IPS in place
  • 11.5.1.1 Covert malware channel detection (SP)
  • 11.5.2 Change detection mechanism (FIM)
  • 11.6.1 Payment page change and tamper detection
  • 12.10.3 24/7 incident response coverage
  • 12.10.5 IRP includes monitoring and response to security control alerts
  • 12.3.3 Cryptographic cipher suites and protocols inventory
  • 12.4.1 Executive management responsibility for the PCI DSS compliance program (service providers)
  • 12.5.1 Inventory of system components in scope
  • 12.6.1 Formal security awareness program implemented
  • 2.2.1 Configuration standards are developed, implemented, and maintained to: • Cover all system components. • Address all known security vulnerabilities. • Be consistent with industry-accepted system hardening standards or vendor hardening recommendations. • Be updated
  • 2.2.5 Insecure services or protocols documented
  • 2.3.2 Wireless encryption keys rotated
  • 3.5.1.1 Hashes of PAN use keyed cryptographic functions
  • 3.7.7 Prevent unauthorised substitution of keys
  • 4.2.1.1 Inventory of trusted keys and certificates
  • 5.3.4 Audit logs for anti-malware enabled
  • 5.4.1 Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks
  • 6.2.4 Coding practices prevent common attacks
  • 6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
  • 6.4.2 For public-facing web applications, an automated technical solution is deployed that continually detects and prevents web-based attacks, with at least the following: • Is installed in front of public-facing web applications and is configured
  • 8.2.6 Inactive user accounts are removed or disabled within 90 days of inactivity
  • 8.2.7 Third-party access managed
  • 8.3.4 Invalid authentication attempts are limited by: • Locking out the user ID after not more than 10 attempts. • Setting the lockout duration to a minimum of 30 minutes or until the user's identity
  • 8.3.9 Password change frequency if only factor
  • 8.5.1 MFA systems are implemented as follows: • The MFA system is not susceptible to replay attacks. • MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by
  • 9.2.3 Physical access to networking and telecommunications hardware restricted
  • 9.3.4 Visitor log retention
  • 9.4.4 Management approval for media moved outside the facility
  • 9.4.5 Inventory logs of electronic media
  • 9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months
  • 9.5.1 POI device protection
  • 9.5.1.2 POI tamper inspection
  • 6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
  • 6.4.3 All payment page scripts that are loaded and executed in the consumer's browser are managed as follows: • A method is implemented to confirm that each script is authorized. • A method is implemented

FedRAMP High · 69 controls

  • AC-17(1) Monitoring and Control
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-22 Publicly Accessible Content
  • AC-6(9) Log Use of Privileged Functions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7 Audit Record Reduction and Report Generation
  • AU-7(1) Automatic Processing
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • CA-8 Penetration Testing
  • CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-6(1) Automated Reporting
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]
  • MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
  • MA-3(1) Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications
  • MA-4 Nonlocal Maintenance
  • PE-13(1) Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a
  • PE-13(2) Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-10 Network Disconnect
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-5 Denial-of-Service Protection
  • SC-7(12) Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]
  • SC-7(4) External Telecommunications Services
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
  • SI-4(16) System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 69 controls

  • AC-17(1) Monitoring and Control
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-22 Publicly Accessible Content
  • AC-6(9) Log Use of Privileged Functions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7 Audit Record Reduction and Report Generation
  • AU-7(1) Automatic Processing
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • CA-8 Penetration Testing
  • CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-6(1) Automated Reporting
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]
  • MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
  • MA-3(1) Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications
  • MA-4 Nonlocal Maintenance
  • PE-13(1) Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a
  • PE-13(2) Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-10 Network Disconnect
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-5 Denial-of-Service Protection
  • SC-7(12) Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]
  • SC-7(4) External Telecommunications Services
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
  • SI-4(16) System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(7) Integration of Detection and Response

NIST SP 800-53 Rev 5 · 54 controls

  • NIST800-AC-23 Data Mining Protection. Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining
  • NIST800-AC-7 Unsuccessful logon attempts
  • NIST800-AC-9 Previous Logon Notification. Notify the user, upon successful logon to the system, of the date and time of the last logon
  • NIST800-AU-1 Policy and procedures for audit and accountability
  • NIST800-AU-10 Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]
  • NIST800-AU-12 Audit record generation
  • NIST800-AU-14 Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and
  • NIST800-AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
  • NIST800-AU-2 Event logging
  • NIST800-AU-3 Content of audit records
  • NIST800-AU-4 Audit log storage capacity
  • NIST800-AU-5 Response to audit logging process failures
  • NIST800-AU-6 Audit record review, analysis, and reporting
  • NIST800-AU-7 Audit record reduction and report generation
  • NIST800-AU-8 Time stamps
  • NIST800-AU-9 Protection of audit information
  • NIST800-CA-7 Continuous monitoring
  • NIST800-CA-8 Penetration testing
  • NIST800-CA-9 Internal system connections
  • NIST800-CM-2 Baseline configuration
  • NIST800-CM-6 Configuration settings
  • NIST800-IR-3 Incident response testing
  • NIST800-IR-5 Incident monitoring
  • NIST800-PE-10 Emergency shutoff
  • NIST800-PE-20 Asset Monitoring and Tracking. Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined]
  • NIST800-PM-12 Insider Threat Program. Implement an insider threat program that includes a cross-discipline insider threat incident handling team
  • NIST800-PM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be
  • NIST800-PM-16 Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence
  • NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
  • NIST800-RA-10 Threat hunting
  • NIST800-RA-5 Vulnerability monitoring and scanning
  • NIST800-SC-15 Collaborative computing devices and applications
  • NIST800-SC-17 Public key infrastructure certificates
  • NIST800-SC-18 Mobile Code. Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system
  • NIST800-SC-38 Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]
  • NIST800-SC-43 Usage Restrictions. Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ; and Authorize, monitor, and control the use of such components within the system
  • NIST800-SC-45 System Time Synchronization. Synchronize system clocks within and between systems and system components
  • NIST800-SI-1 Policy and procedures for system and information integrity
  • NIST800-SI-11 Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined]
  • NIST800-SI-16 Memory protection
  • NIST800-SI-2 Flaw remediation
  • NIST800-SI-20 Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [organization-defined]
  • NIST800-SI-4 System monitoring
  • NIST800-SI-5 Security alerts, advisories, and directives
  • NIST800-SI-6 Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defined]; Alert [organization-defined] to failed security and privacy verification tests; and [organization-defined] when anomalies
  • NIST800-SI-7 Software, firmware, and information integrity
  • NIST800-SR-4 Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined]
  • NIST800-SR-9 Tamper Resistance and Detection. Implement a tamper protection program for the system, system component, or system service
  • SP800-53-AU Audit and Accountability Family
  • SP800-53-CA Assessment, Authorization, and Monitoring Family
  • SP800-53-CM Configuration Management Family
  • SP800-53-IR Incident Response Family
  • SP800-53-MA Maintenance Family
  • SP800-53-SI System and Information Integrity Family

CIS Controls v8 · 48 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-3.14 Log Sensitive Data Access
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.10 Retain Audit Logs
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.12 Collect Service Provider Logs
  • CIS-8.2 Collect Audit Logs
  • CIS-8.3 Ensure Adequate Audit Log Storage
  • CIS-8.4 Standardize Time Synchronization
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-8.6 Collect DNS Query Audit Logs
  • CIS-8.7 Collect URL Request Audit Logs
  • CIS-8.8 Collect Command-Line Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
  • AC-17(1) Monitoring and Control
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(4) Automated Audit Actions
  • AC-22 Publicly Accessible Content
  • AC-6(9) Log Use of Privileged Functions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7 Audit Record Reduction and Report Generation
  • AU-7(1) Automatic Processing
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • CA-8 Penetration Testing
  • CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
  • CM-6 Configuration Settings
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-5 Incident Monitoring
  • MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
  • MA-4 Nonlocal Maintenance
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-10 Network Disconnect
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-5 Denial-of-Service Protection
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-4 System Monitoring
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7 Software, Firmware, and Information Integrity
  • AC-17(1) Monitoring and Control
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(4) Automated Audit Actions
  • AC-22 Publicly Accessible Content
  • AC-6(9) Log Use of Privileged Functions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7 Audit Record Reduction and Report Generation
  • AU-7(1) Automatic Processing
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-6 Configuration Settings
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-5 Incident Monitoring
  • MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
  • MA-4 Nonlocal Maintenance
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-10 Network Disconnect
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-5 Denial-of-Service Protection
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-4 System Monitoring
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7 Software, Firmware, and Information Integrity

CMMC 2.0 · 27 controls

  • AC-22 Publicly Accessible Content
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-4 Audit Log Storage Capacity
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-8 Time Stamps
  • AU-9 Protection of Audit Information
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • CM-2 Baseline Configuration
  • CM-6 Configuration Settings
  • IR-1 Policy and Procedures
  • IR-5 Incident Monitoring
  • MA-4 Nonlocal Maintenance
  • PE-6 Monitoring Physical Access
  • PE-8 Visitor Access Records
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-15 Collaborative Computing Devices and Applications
  • SC-5 Denial-of-Service Protection
  • SI-2 Flaw Remediation
  • SI-4 System Monitoring
  • SI-5 Security Alerts, Advisories, and Directives

ISO 27002:2022 · 16 controls

  • 5.24 Information security incident management planning and preparation
  • 5.28 Collection of evidence
  • 5.7 Threat intelligence
  • 6.8 Information security event reporting
  • 7.4 Physical security monitoring
  • 8.1 User endpoint devices
  • 8.12 Data leakage prevention
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization
  • 8.18 Use of privileged utility programs
  • 8.21 Security of network services
  • 8.34 Protection of information systems during audit testing
  • 8.7 Protection against malware
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 27001:2022 · 14 controls

  • 5.24 Information security incident management planning and preparation
  • 5.28 Collection of evidence
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.7 Threat intelligence
  • 6.8 Information security event reporting
  • 7.4 Physical security monitoring
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.27 Secure system architecture and engineering principles
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

HIPAA Security Rule · 13 controls

NIST SP 800-66 Rev 2 · 13 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

ISO 27701:2019 · 9 controls

  • 5.5 Support
  • 5.6 Operation
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.13 Information security incident management
  • 6.9 Operations security
  • 6.9.4 Logging and monitoring
  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management
  • 6.9.7 Information systems audit considerations

NIST SP 800-218 · 9 controls

  • ASBv3-NS-8 Detect and disable insecure services and protocols
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • ASBv3-PV-7 Conduct regular red team operations
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 7 controls

  • C5-OPS-16 Logging and Monitoring - Configuration
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • C5-PSS-11 Images for Virtual Machines and Containers

NIST SP 800-171 Rev 3 · 6 controls

  • ASD37-02 Patch applications (Essential)
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-19 Patch operating systems (Essential)

ISO/IEC 42001:2023 · 5 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.3.3 Reporting of concerns
  • A.6 AI system life cycle
  • A.6.2.6 AI system operation and monitoring
  • A.6.2.8 AI system event logging
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

DORA · 4 controls

ACSC Essential Eight · 3 controls

NIST SP 800-161 Rev 1 · 3 controls

AICPA SOC 3 · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-172 · 2 controls

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

UK Cyber Essentials · 2 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.3 Critical and High Updates within 14 Days

APRA CPS 234 · 1 control

  • AUCDR-IS-4 Formal vulnerability management program

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

GDPR · 1 control

ISO 22301:2019 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 27018 · 1 control

  • A.10.4 Control and logging of data restoration

ISO/IEC 27018:2019 · 1 control

  • A.10.4 Control and logging of data restoration

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 CC7.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 612 it maps to, and the evidence behind each claim, over MCP and REST.