Frameworks / SOC 2 / SOC2-CC7.3 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC7.3: CC7.3 Evaluating security events to identify incidents Security events are evaluated to decide whether they could cause, or have caused, a failure to meet objectives, and if so action is taken to prevent or address the failure. Points of focus: incident response procedures exist and their effectiveness is evaluated periodically; people running the security programme are told of detected events and review them; procedures analyse incidents and their impact on the system; and in privacy engagements, events are assessed for unauthorised use or disclosure of personal information and legal non-compliance, and the personal information affected is identified. The 2022 revision adds, for confidentiality engagements, assessing whether detected events could have or did expose or misuse confidential information and, where they did, identifying the information affected and acting to prevent a repeat.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 136 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AU-6(3) Correlate Audit Record Repositories IR-1 Policy and Procedures IR-2 Incident Response Training IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-6(1) Automated Reporting IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-8 Incident Response Plan SA-1 Policy and Procedures SA-2 Allocation of Resources SI-11 Error Handling SI-2 Flaw Remediation SI-4(5) System-Generated Alerts SI-5 Security Alerts, Advisories, and Directives SI-7(7) Integration of Detection and Response AU-6(3) Correlate Audit Record Repositories IR-1 Policy and Procedures IR-2 Incident Response Training IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-6(1) Automated Reporting IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-8 Incident Response Plan SA-1 Policy and Procedures SA-2 Allocation of Resources SI-11 Error Handling SI-2 Flaw Remediation SI-4(5) System-Generated Alerts SI-5 Security Alerts, Advisories, and Directives SI-7(7) Integration of Detection and Response CIS-13.1 Centralize Security Event Alerting CIS-13.11 Tune Security Event Alerting Thresholds CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.9 Establish and Maintain Security Incident Thresholds CIS-18.4 Validate Security Measures CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.11 Conduct Audit Log Reviews NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved NIST-CSF-RS.MA-02 Incident reports are triaged and validated NIST-CSF-RS.MA-03 Incidents are categorized and prioritized 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.28 Collection of evidence 6.8 Information security event reporting 8.15 Logging 8.16 Monitoring activities 8.8 Management of technical vulnerabilities 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 12.10.3 12.10.3 Incident response personnel available 24/7 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.28 Collection of evidence 6.8 Information security event reporting 8.16 Monitoring activities ASBv3-IR-2 Preparation - setup incident notification ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts ASBv3-IR-4 Detection and analysis - investigate an incident ASBv3-IR-5 Detection and analysis - prioritize incidents SEC04-BP03 Correlate and enrich security alerts SEC10-BP02 Develop incident management plans SEC10-BP04 Develop and test security incident response playbooks C5-SIM-01 Policy for security incident management C5-SIM-02 Processing of security incidents C5-SIM-03 Documentation and reporting of security incidents 03.03.05 Audit Record Review, Analysis, and Reporting 03.06.01 Incident Handling 03.06.02 Incident Monitoring, Reporting, and Response Assistance CPS234-30 Detection and Response Mechanisms CPS234-P25 Response Plan Content and Escalation Mechanisms ASD37-28 Continuous incident detection and response (Excellent) ASD37-31 Hunt to discover incidents (Very Good) 6.13 Information security incident management 6.13.1 Management of information security incidents and improvements 3.6.1e Establish Security Operations Center (SOC) 3.6.2e Establish and Maintain a Cyber Incident Response Team E8-APP-ML2 Application Control (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure CPS230-27 Identification and Escalation of Incidents and Near Misses CFTC-SS-16 Security Incident Response Plan and Testing Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC7.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 136 it maps to, and the evidence behind each claim, over MCP and REST.