SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC7.4: CC7.4 Responding to security incidents

Identified security incidents are handled through a defined response programme that understands, contains, remediates and communicates them as appropriate. Points of focus: roles for designing, running and maintaining the programme are assigned, including outside help; incidents are contained, their ongoing effects mitigated and their threats ended by closing vulnerabilities and removing unauthorised access; operations and data are restored to an interim workable state; communication protocols reach affected parties; the nature and severity of each incident drive the response time frame and containment approach; vulnerabilities are remediated and the remediation documented and communicated; the design of the response is evaluated periodically; incidents are reviewed for patterns and root causes that call for system change; and in privacy engagements, unauthorised use or disclosure is reported to data subjects, authorities and others as required, and those responsible are sanctioned where appropriate. The 2022 revision frames remediation as resolving the identified vulnerabilities and, for privacy engagements, adds applying defined breach response procedures once a privacy incident is confirmed.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 494 controls across 146 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 20 controls

  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AU-5 Response to Audit Logging Process Failures
  • CA-9 Internal System Connections
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • IR-6 Incident Reporting
  • IR-7 Incident Response Assistance
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-8 Incident Response Plan
  • IR-9 Information Spillage Response (IR-9)
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • PS-8 Personnel Sanctions
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 20 controls

  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AU-5 Response to Audit Logging Process Failures
  • CA-9 Internal System Connections
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • IR-6 Incident Reporting
  • IR-7 Incident Response Assistance
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-8 Incident Response Plan
  • IR-9 Information Spillage Response (IR-9)
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • PS-8 Personnel Sanctions
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-7(7) Integration of Detection and Response

NIST SP 800-53 Rev 5 · 18 controls

  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated

PCI DSS 4.0 · 14 controls

  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations
  • 2.2.2 2.2.2 Vendor default accounts managed

CIS Controls v8 · 10 controls

  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • CIS-17.7 Conduct Routine Incident Response Exercises
  • CIS-7.2 Establish and Maintain a Remediation Process

ISO 27001:2022 · 7 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • 5.29 Information security during disruption
  • 8.16 Monitoring activities

CMMC 2.0 · 6 controls

ISO 22320:2018 · 6 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.2 Incident management process
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

ISO 27002:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 5.29 Information security during disruption
  • 6.8 Information security event reporting

DORA · 5 controls

ISO 22301:2019 · 5 controls

  • 10.2 Continual improvement
  • 8.4.2 Response structure
  • 8.4.3 Warning and communication
  • 8.4.4 Business continuity plans
  • 8.5 Exercise programme
  • PICERL-C2 System Backup
  • PICERL-C3 Long-Term Containment
  • PICERL-L3 Plan Improvement
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation

APRA CPS 234 · 4 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-30 Endpoint detection and response (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASBv3-GS-7 Define and implement logging, threat detection and incident response strategy
  • ASBv3-IR-1 Preparation - update incident response plan and handling process
  • ASBv3-IR-2 Preparation - setup incident notification
  • ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling

C5 (Germany) · 4 controls

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-01 Policy for security incident management
  • C5-SIM-02 Processing of security incidents
  • C5-SIM-03 Documentation and reporting of security incidents
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

HIPAA Security Rule · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

PCI P2PE · 4 controls

  • PCI-P2PE-05 Roles and responsibilities definition
  • PCI-P2PE-21 Incident detection and classification
  • PCI-P2PE-22 Incident response and containment
  • PCI-P2PE-25 Post-incident review and improvement

PCI PIN Security · 4 controls

  • PCI-PIN-05 Roles and responsibilities definition
  • PCI-PIN-23 Regulatory reporting requirements
  • PCI-PIN-24 Customer notification procedures
  • PCI-PIN-25 Post-incident review and improvement

PCI SSF · 4 controls

  • PCI-SSF-05 Roles and responsibilities definition
  • PCI-SSF-21 Incident detection and classification
  • PCI-SSF-24 Customer notification procedures
  • PCI-SSF-25 Post-incident review and improvement

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

ISO/IEC 30111:2019 · 3 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • 30111-5.2 Vulnerability handling team

ISO/IEC 42001:2023 · 3 controls

  • 10.2 Nonconformity and corrective action
  • 7.4 Communication
  • A.8.4 Communication of incidents

NIST SP 1800-32 · 3 controls

  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-CC7.5 CC7.5 - Incident Recovery
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards
  • SOCI-S30CB Statutory incident response planning
  • SOCI-S35AB Ministerial authorisation for government assistance
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights
  • 58.1 Scope
  • 58.3 Definitions

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.7 Emergency and Incident Response
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training

Bahrain PDPL · 2 controls

  • BB-DPA-2 Section 2 - Interpretation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CFTC-SS-16 Security Incident Response Plan and Testing
  • CFTC-SS-19 Prompt Notification to the Commission

EU AI Act · 2 controls

  • EUAI-Art.55 Obligations of providers of GPAI models with systemic risk
  • EUAI-Art.73 Reporting of serious incidents
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications

ISO 27701:2019 · 2 controls

  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PI-01 Personnel Security Screening
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 2 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIS2 Directive · 2 controls

  • Art.21.2.b Incident handling
  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

NIST SP 800-190 · 2 controls

  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation

Saudi Arabia PDPL · 2 controls

  • SA-PDPL-16 Data breach notification requirements
  • SA-PDPL-17 Security incident response procedures
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.3 Incident Response

South Korea ISMS-P · 2 controls

  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-05 Incident Response
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border

UK Bribery Act 2010 · 2 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • OB-OPS.2 Performance Standards
  • OB-OPS.4 Incident Management
  • UK-TSA-MON-02 Incident Notification
  • UK-TSA-NET-01 Security Architecture
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • AEO-12 Crisis Management and Incident Recovery
  • AZ-DPA-2 Article 2 - Basic Concepts
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CTDPA-1 Definitions
  • CAT-D5-1 Incident planning and strategy

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • 62351-2 Glossary of terms
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition
  • ISO20000-11 Incident management

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy

ISO/IEC 27043:2015 · 1 control

  • ISO27043-04 Roles and responsibilities definition
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions

ISO/SAE 21434 · 1 control

  • ISO21434-04 Roles and responsibilities definition

ITIL 4 · 1 control

  • ITIL4-11 Incident management
  • BIPA-SEC5-1 Biometric Identifier Definition
  • NFPA1600-6.3 Emergency Response Operations

NIST SP 800-172 · 1 control

  • 3.6.2e Establish and Maintain a Cyber Incident Response Team
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • RIDTPPA-1 Scope, Applicability, Definitions
  • SCA-S2 Interpretation and Definitions
  • SWE-2 Relationship to GDPR

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TSSR-NOT-2 Security Incident Notification
  • TEXASTDPSA-2 Consumer Rights
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern

Uruguay DPL · 1 control

  • URUGUAY-4 Security and Cross-Border

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC7.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 494 it maps to, and the evidence behind each claim, over MCP and REST.