SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC7.3: CC7.3 Evaluating security events to identify incidents

Security events are evaluated to decide whether they could cause, or have caused, a failure to meet objectives, and if so action is taken to prevent or address the failure. Points of focus: incident response procedures exist and their effectiveness is evaluated periodically; people running the security programme are told of detected events and review them; procedures analyse incidents and their impact on the system; and in privacy engagements, events are assessed for unauthorised use or disclosure of personal information and legal non-compliance, and the personal information affected is identified. The 2022 revision adds, for confidentiality engagements, assessing whether detected events could have or did expose or misuse confidential information and, where they did, identifying the information affected and acting to prevent a repeat.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 136 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 16 controls

  • AU-6(3) Correlate Audit Record Repositories
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-6(1) Automated Reporting
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-8 Incident Response Plan
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 16 controls

  • AU-6(3) Correlate Audit Record Repositories
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-6(1) Automated Reporting
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-8 Incident Response Plan
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SI-11 Error Handling
  • SI-2 Flaw Remediation
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-7(7) Integration of Detection and Response

CMMC 2.0 · 13 controls

NIST SP 800-53 Rev 5 · 13 controls

CIS Controls v8 · 10 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.9 Establish and Maintain Security Incident Thresholds
  • CIS-18.4 Validate Security Measures
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized

ISO 27001:2022 · 7 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.28 Collection of evidence
  • 6.8 Information security event reporting
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.8 Management of technical vulnerabilities

PCI DSS 4.0 · 6 controls

  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations

ISO 27002:2022 · 5 controls

  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 6.8 Information security event reporting
  • 8.16 Monitoring activities
  • ASBv3-IR-2 Preparation - setup incident notification
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-5 Detection and analysis - prioritize incidents
  • SEC04-BP03 Correlate and enrich security alerts
  • SEC10-BP02 Develop incident management plans
  • SEC10-BP04 Develop and test security incident response playbooks

C5 (Germany) · 3 controls

  • C5-SIM-01 Policy for security incident management
  • C5-SIM-02 Processing of security incidents
  • C5-SIM-03 Documentation and reporting of security incidents

DORA · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

  • 03.03.05 Audit Record Review, Analysis, and Reporting
  • 03.06.01 Incident Handling
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

APRA CPS 234 · 2 controls

  • CPS234-30 Detection and Response Mechanisms
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-31 Hunt to discover incidents (Very Good)

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements

NIST SP 800-172 · 2 controls

  • 3.6.1e Establish Security Operations Center (SOC)
  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

NIST SP 800-66 Rev 2 · 2 controls

  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CFTC-SS-16 Security Incident Response Plan and Testing

EU AI Act · 1 control

ISO 22301:2019 · 1 control

NIS2 Directive · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC7.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 136 it maps to, and the evidence behind each claim, over MCP and REST.