Frameworks / SOC 2 / SOC2-CC7.4 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC7.4: CC7.4 Responding to security incidents Identified security incidents are handled through a defined response programme that understands, contains, remediates and communicates them as appropriate. Points of focus: roles for designing, running and maintaining the programme are assigned, including outside help; incidents are contained, their ongoing effects mitigated and their threats ended by closing vulnerabilities and removing unauthorised access; operations and data are restored to an interim workable state; communication protocols reach affected parties; the nature and severity of each incident drive the response time frame and containment approach; vulnerabilities are remediated and the remediation documented and communicated; the design of the response is evaluated periodically; incidents are reviewed for patterns and root causes that call for system change; and in privacy engagements, unauthorised use or disclosure is reported to data subjects, authorities and others as required, and those responsible are sanctioned where appropriate. The 2022 revision frames remediation as resolving the identified vulnerabilities and, for privacy engagements, adds applying defined breach response procedures once a privacy incident is confirmed.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 494 controls across 146 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2(13) Disable Accounts for High-Risk Individuals AU-5 Response to Audit Logging Process Failures CA-9 Internal System Connections IR-1 Policy and Procedures IR-2 Incident Response Training IR-3 Incident Response Testing IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2)) IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-6 Incident Reporting IR-7 Incident Response Assistance IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-8 Incident Response Plan IR-9 Information Spillage Response (IR-9) IR-9(2) Information Spillage Response | Training (IR-9(2)) IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3)) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) PS-8 Personnel Sanctions SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-7(7) Integration of Detection and Response AC-2(13) Disable Accounts for High-Risk Individuals AU-5 Response to Audit Logging Process Failures CA-9 Internal System Connections IR-1 Policy and Procedures IR-2 Incident Response Training IR-3 Incident Response Testing IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2)) IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-6 Incident Reporting IR-7 Incident Response Assistance IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-8 Incident Response Plan IR-9 Information Spillage Response (IR-9) IR-9(2) Information Spillage Response | Training (IR-9(2)) IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3)) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) PS-8 Personnel Sanctions SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-7(7) Integration of Detection and Response NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-02 Incident reports are triaged and validated NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied NIST-CSF-RS.MI-01 Incidents are contained NIST-CSF-RS.MI-02 Incidents are eradicated 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 11.4.4 11.4.4 Correct exploitable findings from penetration tests 12.10.1 12.10.1 Incident response plan ready for activation 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.10.3 12.10.3 Incident response personnel available 24/7 12.10.4 12.10.4 Periodic training for incident response personnel 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations 2.2.2 2.2.2 Vendor default accounts managed CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.5 Assign Key Roles and Responsibilities CIS-17.6 Define Mechanisms for Communicating During Incident Response CIS-17.7 Conduct Routine Incident Response Exercises CIS-7.2 Establish and Maintain a Remediation Process 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.28 Collection of evidence 5.29 Information security during disruption 8.16 Monitoring activities ISO-22320-5.1 General process requirements ISO-22320-5.2 Incident management process ISO-22320-5.3 Incident management structure (command) ISO-22320-5.4 Roles and responsibilities ISO-22320-B Annex B: Incident management plan structure ISO-22320-C Annex C: Incident management task examples 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.28 Collection of evidence 5.29 Information security during disruption 6.8 Information security event reporting 10.2 Continual improvement 8.4.2 Response structure 8.4.3 Warning and communication 8.4.4 Business continuity plans 8.5 Exercise programme PICERL-C2 System Backup PICERL-C3 Long-Term Containment PICERL-L3 Plan Improvement PICERL-P2 Risk Assessment PICERL-P3 CSIRT Formation CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls CPS234-P24 Information Security Response Plans CPS234-P25 Response Plan Content and Escalation Mechanisms ASD37-28 Continuous incident detection and response (Excellent) ASD37-30 Endpoint detection and response (Very Good) ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) ASBv3-GS-7 Define and implement logging, threat detection and incident response strategy ASBv3-IR-1 Preparation - update incident response plan and handling process ASBv3-IR-2 Preparation - setup incident notification ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents C5-SIM-01 Policy for security incident management C5-SIM-02 Processing of security incidents C5-SIM-03 Documentation and reporting of security incidents FFIEC-05 Roles and responsibilities definition FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement PCI-P2PE-05 Roles and responsibilities definition PCI-P2PE-21 Incident detection and classification PCI-P2PE-22 Incident response and containment PCI-P2PE-25 Post-incident review and improvement PCI-PIN-05 Roles and responsibilities definition PCI-PIN-23 Regulatory reporting requirements PCI-PIN-24 Customer notification procedures PCI-PIN-25 Post-incident review and improvement PCI-SSF-05 Roles and responsibilities definition PCI-SSF-21 Incident detection and classification PCI-SSF-24 Customer notification procedures PCI-SSF-25 Post-incident review and improvement API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management RMD-1 Reference Data Management IS.AR.215 Information Security Incident Response IS.D.OR.225 External Reporting of Information Security Events IS.I.OR.225 External Reporting IEC62304-5.2 Software Requirements Analysis IEC62304-5.3 Software Architectural Design IEC62304-7.2 Risk Control Measures IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO-15189-5.1 Legal entity ISO-15189-5.4 Structure and authority ISO-15189-6.7 Service agreements ISO-19650-1-4 Information management concepts ISO-19650-1-7 Common Data Environment (CDE) concept ISO-19650-3-5.3 Trigger events for information exchange ISO23894-1 Scope of AI Risk Management ISO23894-3 AI-Specific Terminology ISO23894-6.2 Scope, Context and Criteria 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents 27557-1 Scope 27557-3 Terms and definitions 27557-6.2 Scope, context, and criteria for privacy 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles 30111-3 Terms and definitions 30111-5.1 Organizational policy 30111-5.2 Vulnerability handling team 10.2 Nonconformity and corrective action 7.4 Communication A.8.4 Communication of incidents SSAE18-CC7.4 CC7.4 - Incident Response SSAE18-CC7.5 CC7.5 - Incident Recovery SSAE18-PI1.1 PI1.1 - Processing Integrity Definition SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards SOCI-S30CB Statutory incident response planning SOCI-S35AB Ministerial authorisation for government assistance TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-2 Lawful Processing and Consent TRINIDAD-3 Data Subject Rights 58.1 Scope 58.3 Definitions APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information CPS230-13 Board Accountability for Operational Risk Management CPS230-27 Identification and Escalation of Incidents and Near Misses 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.7 Emergency and Incident Response AL-DPA-1 Scope and Definitions AL-DPA-3 Lawful Basis for Processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training BB-DPA-2 Section 2 - Interpretation BB-DPA-20 Sections 50-60 - Registration and Responsibilities CFTC-SS-16 Security Incident Response Plan and Testing CFTC-SS-19 Prompt Notification to the Commission EUAI-Art.55 Obligations of providers of GPAI models with systemic risk EUAI-Art.73 Reporting of serious incidents FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FEDRAMP-CM-6 Configuration Settings FEDRAMP-CP-9 System Backup UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements ISO-20400-4.2 Principles of sustainable procurement ISO-20400-7.2 Integrating sustainability into specifications 6.13 Information security incident management 6.13.1 Management of information security incidents and improvements ISO28001-PC-04 Supply Chain Continuity Planning ISO28001-PI-01 Personnel Security Screening ISO-41001-4.1 Understanding the organization and its context ISO-41001-4.3 Determining the scope of the FM management system ISO-56002-4.3 Determining the scope of the innovation management system ISO-56002-8.3.4 Develop solutions ISO8000-DQM-02 Data Quality Dimensions ISO8000-MDG-03 Continuous Improvement ISO-17025-5.1 Legal entity ISO-17025-5.4 Personnel for the management system ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 27011-1 Scope 27011-3 Terms and definitions 27014-1 Scope 27014-3 Terms and definitions 27400-3 Terms and definitions 27400-6.5 Security monitoring and incident response 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding Art.21.2.b Incident handling Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation SA-PDPL-16 Data breach notification requirements SA-PDPL-17 Security incident response procedures C1 Organizational Boundary C3 Scope 1 and 2 Coverage IM8-RES.2 Disaster Recovery IM8-RES.3 Incident Response ISMSP-SYS-04 Vulnerability Management ISMSP-SYS-05 Incident Response TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-4 Security and Cross-Border Section 6(5) Definition of Foreign Public Official Section 8 Definition of Associated Person D.1 Incident Response Planning D.2 Incident Reporting UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11) UKGDPRREG-3 Controller and Processor (Articles 24-43) OB-OPS.2 Performance Standards OB-OPS.4 Incident Management UK-TSA-MON-02 Incident Notification UK-TSA-NET-01 Security Architecture US-SEC-DA-SC-01 Howey Test Application US-SEC-DA-SC-02 Registration Requirements CFR211-A-3 Section 211.3 - Definitions E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure AWWA-1.1 Security Policy and Governance AEO-12 Crisis Management and Incident Recovery AZ-DPA-2 Article 2 - Basic Concepts CPG-6.B Supply Chain Incident Reporting COBIT-BAI02 Managed requirements definition CA-12 Deploys Through Policies and Procedures CA-ITSG33-SC-01 Security Control Catalogue CAT-D5-1 Incident planning and strategy GDPR-Art.33 Notification of a personal data breach to the supervisory authority ICP-1 Objectives, Powers and Responsibilities of the Supervisor 62351-2 Glossary of terms ISO-14064-1-5.1 Organizational boundaries ISO-26262-3-5 Item definition ISO20000-11 Incident management ISO27003-4.3 Determining the scope of the information security management system 27007-5.2 Audit Programme Objectives 27010-16.1 Continuity of Sharing ISO27043-04 Roles and responsibilities definition 27050-1.4 Terms and definitions 29115-3 Terms and definitions 29134-3 Terms and definitions ISO21434-04 Roles and responsibilities definition ITIL4-11 Incident management BIPA-SEC5-1 Biometric Identifier Definition NFPA1600-6.3 Emergency Response Operations 3.6.2e Establish and Maintain a Cyber Incident Response Team NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation RIDTPPA-1 Scope, Applicability, Definitions SOC-CY-S2 System Operations SCA-S2 Interpretation and Definitions SWE-2 Relationship to GDPR TAIWAN-3 Data Subject Rights TSSR-NOT-2 Security Incident Notification TEXASTDPSA-2 Consumer Rights 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern CYB-5 Cyber Incident Response Plan URUGUAY-4 Security and Cross-Border VIRGINIAVCDPA-3 Sensitive Data Consent and Children WCAGREC-3 Principle 3: Understandable SO2.2 Digital health architecture blueprint Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC7.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 494 it maps to, and the evidence behind each claim, over MCP and REST.