SOC 2
CC - Common Criteria (Security)

SOC 2 CC7.5: Identifies the root cause of security incidents

Identifies, develops, and implements activities to recover from identified security incidents

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 240 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • NIST-CSF-RS.MI-02 Incidents are eradicated

NIST SP 800-53 Rev 5 · 8 controls

APRA CPS 234 · 4 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-36 System recovery capabilities (Very Good)

FedRAMP High · 4 controls

  • CP-10 System Recovery and Reconstitution
  • IR-4 Incident Handling
  • IR-8 Incident Response Plan
  • IR-9(3) Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:

FedRAMP Moderate · 4 controls

  • CP-10 System Recovery and Reconstitution
  • IR-4 Incident Handling
  • IR-8 Incident Response Plan
  • IR-9(3) Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:

API 1164 · 3 controls

  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

C5 (Germany) · 3 controls

  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • C5-SIM-03 Documentation and reporting of security incidents
  • C5-SIM-05 Evaluation and learning process

DORA · 3 controls

  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

IEC 62443 · 3 controls

ISO 22320:2018 · 3 controls

ISO 27002:2022 · 3 controls

  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents

ISO 27019 · 3 controls

NIST SP 1800-32 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-218 · 3 controls

  • CP-10 System Recovery and Reconstitution
  • IR-4 Incident Handling
  • IR-8 Incident Response Plan
  • CP-10 System Recovery and Reconstitution
  • IR-4 Incident Handling
  • IR-8 Incident Response Plan
  • CP-10 System Recovery and Reconstitution
  • IR-4 Incident Handling
  • IR-8 Incident Response Plan

PCI DSS 4.0 · 3 controls

  • 10.7.3 Failure response timeline
  • 12.10.6 IRP refined based on lessons learned
  • 12.10.7 Response procedures for PAN detection in unexpected locations

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations

Bahrain PDPL · 2 controls

CIS Controls v8 · 2 controls

  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-17.8 Conduct Post-Incident Reviews

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

ISO 22301:2019 · 2 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement

ISO 27001:2022 · 2 controls

  • 5.27 Learning from information security incidents
  • 5.30 ICT readiness for business continuity

ISO/IEC 30111:2019 · 2 controls

ISO/IEC 42001:2023 · 2 controls

  • 10.2 Nonconformity and corrective action
  • A.8.4 Communication of incidents
  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

NIST SP 800-66 Rev 2 · 2 controls

Saudi Arabia PDPL · 2 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • PMF-M.4 Privacy Incident Management
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • 4.4.7 Emergency and Incident Response
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources
  • CA-12 Deploys Through Policies and Procedures

EU AI Act · 1 control

ISO 20000-1 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 1 control

ITIL 4 · 1 control

NIS2 Directive · 1 control

NIST SP 800-171 · 1 control

  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

NIST SP 800-172 · 1 control

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline

NIST SP 800-190 · 1 control

  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

South Korea ISMS-P · 1 control

Taiwan PDPA · 1 control

Uruguay DPL · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 CC7.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 240 it maps to, and the evidence behind each claim, over MCP and REST.