SOC 2 CC7.1: Detection and monitoring procedures for security events are in place
To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities
This control maps to 612 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
12.6.1 Formal security awareness program implemented
2.2.1 Configuration standards are developed, implemented, and maintained to: • Cover all system components. • Address all known security vulnerabilities. • Be consistent with industry-accepted system hardening standards or vendor hardening recommendations. • Be updated
6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
6.4.2 For public-facing web applications, an automated technical solution is deployed that continually detects and prevents web-based attacks, with at least the following: • Is installed in front of public-facing web applications and is configured
8.2.6 Inactive user accounts are removed or disabled within 90 days of inactivity
8.3.4 Invalid authentication attempts are limited by: • Locking out the user ID after not more than 10 attempts. • Setting the lockout duration to a minimum of 30 minutes or until the user's identity
8.5.1 MFA systems are implemented as follows: • The MFA system is not susceptible to replay attacks. • MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by
9.2.3 Physical access to networking and telecommunications hardware restricted
6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
6.4.3 All payment page scripts that are loaded and executed in the consumer's browser are managed as follows: • A method is implemented to confirm that each script is authorized. • A method is implemented
CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]
MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
MA-3(1) Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications
PE-13(1) Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a
PE-13(2) Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an
RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components
SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined
SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
SI-4(16) System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system
SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
SI-4(23) System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]
SI-4(4) Inbound and Outbound Communications Traffic
CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]
MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
MA-3(1) Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications
PE-13(1) Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a
PE-13(2) Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an
RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components
SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined
SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
SI-4(16) System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system
SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
SI-4(23) System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]
SI-4(4) Inbound and Outbound Communications Traffic
NIST800-AC-9 Previous Logon Notification. Notify the user, upon successful logon to the system, of the date and time of the last logon
NIST800-AU-1 Policy and procedures for audit and accountability
NIST800-AU-10 Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]
NIST800-AU-14 Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and
NIST800-AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
NIST800-PE-20 Asset Monitoring and Tracking. Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined]
NIST800-PM-12 Insider Threat Program. Implement an insider threat program that includes a cross-discipline insider threat incident handling team
NIST800-PM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be
NIST800-PM-16 Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence
NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
NIST800-RA-5 Vulnerability monitoring and scanning
NIST800-SC-15 Collaborative computing devices and applications
NIST800-SC-17 Public key infrastructure certificates
NIST800-SC-18 Mobile Code. Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system
NIST800-SC-38 Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]
NIST800-SC-43 Usage Restrictions. Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ; and Authorize, monitor, and control the use of such components within the system
NIST800-SC-45 System Time Synchronization. Synchronize system clocks within and between systems and system components
NIST800-SI-1 Policy and procedures for system and information integrity
NIST800-SI-11 Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined]
NIST800-SI-20 Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [organization-defined]
NIST800-SI-5 Security alerts, advisories, and directives
NIST800-SI-6 Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defined]; Alert [organization-defined] to failed security and privacy verification tests; and [organization-defined] when anomalies
NIST800-SI-7 Software, firmware, and information integrity
NIST800-SR-4 Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined]
NIST800-SR-9 Tamper Resistance and Detection. Implement a tamper protection program for the system, system component, or system service
CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
CM-12(1) Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
MA-3 Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
You are reading one control. How much of SOC 2 have you already done?
SOC 2 CC7.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.