SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC7.2: CC7.2 Monitoring system components for anomalies

System components and their operation are monitored for anomalies that point to malicious acts, natural disasters or errors, and anomalies are analysed to decide whether they are security events. Points of focus: detection policies, procedures and tools are in place, including governance and resourcing for event detection, threat intelligence on new threats and vulnerabilities, and logging of unusual activity; detection is designed to catch potential intrusions, inappropriate access, compromised physical barriers, unauthorised actions by authorised staff, stolen credentials, unauthorised outside access, compromised external parties and unauthorised hardware or software; anomalies are filtered and analysed to identify events; and the detection tools themselves are checked for effective operation.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 237 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 26 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(4) Automated Audit Actions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(3) Correlate Audit Record Repositories
  • CA-7 Continuous Monitoring
  • CM-11 User-Installed Software
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-5 Denial-of-Service Protection
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-7 Software, Firmware, and Information Integrity
  • SR-10 Inspection of Systems or Components (SR-10)
  • SR-11 Component Authenticity (SR-11)

FedRAMP Moderate · 26 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(4) Automated Audit Actions
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(3) Correlate Audit Record Repositories
  • CA-7 Continuous Monitoring
  • CM-11 User-Installed Software
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-5 Denial-of-Service Protection
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-7 Software, Firmware, and Information Integrity
  • SR-10 Inspection of Systems or Components (SR-10)
  • SR-11 Component Authenticity (SR-11)

PCI DSS 4.0 · 26 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.2 10.2.2 Required details recorded for each auditable event
  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.6.1 10.6.1 System clocks synchronized with time-sync technology
  • 10.6.2 10.6.2 Systems configured to correct and consistent time
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.4.2 6.4.2 Automated web attack detection and prevention
  • 9.5.1 9.5.1 Protection of POI devices from tampering
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 5.3.3 5.3.3 Anti-malware covers removable electronic media

CIS Controls v8 · 25 controls

  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-18.4 Validate Security Measures
  • CIS-2.3 Address Unauthorized Software
  • CIS-3.14 Log Sensitive Data Access
  • CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.10 Retain Audit Logs
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.12 Collect Service Provider Logs
  • CIS-8.2 Collect Audit Logs
  • CIS-8.4 Standardize Time Synchronization
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-8.6 Collect DNS Query Audit Logs
  • CIS-8.9 Centralize Audit Logs

NIST SP 800-53 Rev 5 · 21 controls

CMMC 2.0 · 15 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

C5 (Germany) · 8 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-OPS-15 Logging and Monitoring - Accountability
  • C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software
  • C5-PSS-04 Error handling and Logging Mechanisms

ISO 27001:2022 · 8 controls

  • 5.25 Assessment and decision on information security events
  • 5.7 Threat intelligence
  • 7.4 Physical security monitoring
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization 
  • 8.21 Security of network services
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 8 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.7 Threat intelligence
  • 7.4 Physical security monitoring
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization
  • 8.7 Protection against malware
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-LT-2 Enable threat detection for identity and access management
  • ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS)
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • LT-3 Enable logging for security investigation
  • LT-5 Centralize security log management and analysis

HIPAA Security Rule · 6 controls

NIST SP 800-66 Rev 2 · 6 controls

  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-30 Endpoint detection and response (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)
  • ASD37-33 Capture network traffic (Limited)

ACSC Essential Eight · 4 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-APP-ML2 Application Control (ML2)
  • E8-APP-ML3 Application Control (ML3)
  • E8-UAH-ML3 User Application Hardening - Maturity Level 3

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-172 · 4 controls

  • 3.11.2e Threat Hunting
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 3.14.6e Use Threat Indicator Information for Detection
  • 3.6.1e Establish Security Operations Center (SOC)
  • SEC04-BP01 Configure service and application logging
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • SEC04-BP03 Correlate and enrich security alerts

DORA · 3 controls

ISO/IEC 42001:2023 · 3 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.6.2.6 AI system operation and monitoring
  • A.6.2.8 AI system recording of event logs

EU AI Act · 2 controls

  • EUAI-Art.12 Record-keeping (logs)
  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

AICPA SOC 3 · 1 control

  • SOC3-INCIDENT-MGT Incident Response
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile

APRA CPS 234 · 1 control

  • CPS234-30 Detection and Response Mechanisms
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

ISO 22301:2019 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 27701:2019 · 1 control

  • 6.9.4 Logging and monitoring

NIS2 Directive · 1 control

UK Cyber Essentials · 1 control

  • CE-MP.3 Anti-Malware Scans Files on Access and Web Pages

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC7.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 237 it maps to, and the evidence behind each claim, over MCP and REST.