Frameworks / SOC 2 / SOC2-CC7.2 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC7.2: CC7.2 Monitoring system components for anomalies System components and their operation are monitored for anomalies that point to malicious acts, natural disasters or errors, and anomalies are analysed to decide whether they are security events. Points of focus: detection policies, procedures and tools are in place, including governance and resourcing for event detection, threat intelligence on new threats and vulnerabilities, and logging of unusual activity; detection is designed to catch potential intrusions, inappropriate access, compromised physical barriers, unauthorised actions by authorised staff, stolen credentials, unauthorised outside access, compromised external parties and unauthorised hardware or software; anomalies are filtered and analysed to identify events; and the detection tools themselves are checked for effective operation.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 237 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2(12) Account Monitoring for Atypical Usage AC-2(4) Automated Audit Actions AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-6 Audit Record Review, Analysis, and Reporting AU-6(3) Correlate Audit Record Repositories CA-7 Continuous Monitoring CM-11 User-Installed Software CM-8(3) Automated Unauthorized Component Detection IR-1 Policy and Procedures MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1)) RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SA-1 Policy and Procedures SA-2 Allocation of Resources SC-5 Denial-of-Service Protection SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-4(4) Inbound and Outbound Communications Traffic SI-4(5) System-Generated Alerts SI-7 Software, Firmware, and Information Integrity SR-10 Inspection of Systems or Components (SR-10) SR-11 Component Authenticity (SR-11) AC-2(12) Account Monitoring for Atypical Usage AC-2(4) Automated Audit Actions AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-6 Audit Record Review, Analysis, and Reporting AU-6(3) Correlate Audit Record Repositories CA-7 Continuous Monitoring CM-11 User-Installed Software CM-8(3) Automated Unauthorized Component Detection IR-1 Policy and Procedures MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1)) RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SA-1 Policy and Procedures SA-2 Allocation of Resources SC-5 Denial-of-Service Protection SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-4(4) Inbound and Outbound Communications Traffic SI-4(5) System-Generated Alerts SI-7 Software, Firmware, and Information Integrity SR-10 Inspection of Systems or Components (SR-10) SR-11 Component Authenticity (SR-11) 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.1.2 10.2.1.2 Logs capture all administrative actions 10.2.2 10.2.2 Required details recorded for each auditable event 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage 10.4.1 10.4.1 Daily review of security-relevant logs 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review 10.4.2 10.4.2 Periodic review of all other system component logs 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.6.1 10.6.1 System clocks synchronized with time-sync technology 10.6.2 10.6.2 Systems configured to correct and consistent time 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.6.1 11.6.1 Payment page tamper detection 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 2.2.1 2.2.1 System configuration standards maintained 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 5.3.4 5.3.4 Anti-malware audit logs enabled and retained 5.4.1 5.4.1 Mechanisms detect and protect against phishing 6.4.2 6.4.2 Automated web attack detection and prevention 9.5.1 9.5.1 Protection of POI devices from tampering 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 5.3.3 5.3.3 Anti-malware covers removable electronic media CIS-1.5 Use a Passive Asset Discovery Tool CIS-10.5 Enable Anti-Exploitation Features CIS-13.1 Centralize Security Event Alerting CIS-13.11 Tune Security Event Alerting Thresholds CIS-13.2 Deploy a Host-Based Intrusion Detection Solution CIS-13.3 Deploy a Network Intrusion Detection Solution CIS-13.6 Collect Network Traffic Flow Logs CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-18.4 Validate Security Measures CIS-2.3 Address Unauthorized Software CIS-3.14 Log Sensitive Data Access CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.7 Remediate Detected Vulnerabilities CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.10 Retain Audit Logs CIS-8.11 Conduct Audit Log Reviews CIS-8.12 Collect Service Provider Logs CIS-8.2 Collect Audit Logs CIS-8.4 Standardize Time Synchronization CIS-8.5 Collect Detailed Audit Logs CIS-8.6 Collect DNS Query Audit Logs CIS-8.9 Centralize Audit Logs NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved C5-COS-01 Technical safeguards C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-OPS-10 Logging and Monitoring - Concept C5-OPS-11 Logging and Monitoring - Metadata Management Concept C5-OPS-13 Logging and Monitoring - Identification of Events C5-OPS-15 Logging and Monitoring - Accountability C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software C5-PSS-04 Error handling and Logging Mechanisms 5.25 Assessment and decision on information security events 5.7 Threat intelligence 7.4 Physical security monitoring 8.15 Logging 8.16 Monitoring activities 8.17 Clock synchronization 8.21 Security of network services 8.8 Management of technical vulnerabilities 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.7 Threat intelligence 7.4 Physical security monitoring 8.15 Logging 8.16 Monitoring activities 8.17 Clock synchronization 8.7 Protection against malware ASBv3-LT-1 Enable threat detection capabilities ASBv3-LT-2 Enable threat detection for identity and access management ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS) DP-2 Monitor anomalies and threats targeting sensitive data LT-3 Enable logging for security investigation LT-5 Centralize security log management and analysis ASD37-28 Continuous incident detection and response (Excellent) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-30 Endpoint detection and response (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ASD37-33 Capture network traffic (Limited) E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-APP-ML2 Application Control (ML2) E8-APP-ML3 Application Control (ML3) E8-UAH-ML3 User Application Hardening - Maturity Level 3 3.11.2e Threat Hunting 3.14.2e Monitor Organizational Systems with Specialized Capabilities 3.14.6e Use Threat Indicator Information for Detection 3.6.1e Establish Security Operations Center (SOC) SEC04-BP01 Configure service and application logging SEC04-BP02 Capture logs, findings, and metrics in standardized locations SEC04-BP03 Correlate and enrich security alerts 9.1 Monitoring, measurement, analysis and evaluation A.6.2.6 AI system operation and monitoring A.6.2.8 AI system recording of event logs EUAI-Art.12 Record-keeping (logs) EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems SOC3-INCIDENT-MGT Incident Response ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components CPS230-P27 Comprehensive Assessment of the Operational Risk Profile CPS234-30 Detection and Response Mechanisms AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment 9.1 Monitoring, measurement, analysis and evaluation 6.9.4 Logging and monitoring CE-MP.3 Anti-Malware Scans Files on Access and Web Pages Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC7.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 237 it maps to, and the evidence behind each claim, over MCP and REST.