SOC for Cybersecurity - Cybersecurity Risk Management Examination
SOC for Cybersecurity: Security Criteria

SOC for Cybersecurity - Cybersecurity Risk Management Examination SOC-CY-S2: System Operations

Controls over system operations to detect and mitigate processing deviations and security incidents

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 154 controls across 64 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

IEC 62443 · 3 controls

ISO 22320:2018 · 3 controls

ISO 27019 · 3 controls

  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)

Bahrain PDPL · 2 controls

ISO/IEC 30111:2019 · 2 controls

  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

SOC 2 · 2 controls

  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-CC7.5 Identifies the root cause of security incidents

Saudi Arabia PDPL · 2 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • PMF-M.4 Privacy Incident Management
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures

ISO 20000-1 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 1 control

ITIL 4 · 1 control

NIST SP 800-171 · 1 control

  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

NIST SP 800-190 · 1 control

  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

South Korea ISMS-P · 1 control

Taiwan PDPA · 1 control

Uruguay DPL · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SOC for Cybersecurity: Security Criteria

Query this from an agent

The graph holds this control, the 154 it maps to, and the evidence behind each claim, over MCP and REST.