CC7.2
Monitoring of System Components
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.
Points of focus
- Implements detection policies, procedures, and tools on infrastructure and software
- Designs detection measures for compromise, unauthorized actions, credential abuse, and unauthorized access
- Implements filters to analyze anomalies and identify security events
- Monitors detection tools for effective operation
Implementation notes
CC7.2 expects you to monitor system components for anomalies and analyze whether those anomalies are security events. In SaaS practice, centralize auth, cloud control-plane, application, and infrastructure logs into a SIEM or equivalent, define detection use cases for credential abuse, privilege escalation, unusual data access, and perimeter anomalies, and assign on-call ownership for triage. Filter and summarize noise so analysts can identify true security events. Also monitor the monitors: alert when agents stop reporting or log volume drops to zero. Retain logs long enough to support investigations and Type II sampling. Pair CC7.2 with CC7.3 so analyzed events feed a clear path into incident classification.
Audit tip: Pick two or three closed alerts from the period that show anomaly → analysis → security-event decision, plus proof that key log sources stayed connected.
Evidence auditors typically request:
- SIEM or centralized logging architecture diagram and retention settings
- Alert rule catalog with owners and severity
- Sample security alerts with triage notes from the observation period
- On-call / detection tool health checks (failed agent or silent source monitoring)
- Security monitoring policy or SOC runbook
Common gaps
- Logs collected but never reviewed or alerted — storage without detection
- Critical production sources (IdP, cloud audit, Kubernetes API) missing from the pipeline
- Alert fatigue with no documented tuning or ownership
- No process to verify detection tools themselves are healthy
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC7.2 | This control |
| ISO 27001 | A.8.15, A.8.16 | Logging and monitoring activities |
| HIPAA | 164.312(b), 164.308(a)(1)(ii)(D) | Audit controls and information system activity review |
| GDPR | Article 32(1) | Security of processing — monitoring measures |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus