Skip to content
compliancebase
SOC 2CC7 — Monitoring of System Components

CC7.2

Monitoring of System Components

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.

Points of focus

  • Implements detection policies, procedures, and tools on infrastructure and software
  • Designs detection measures for compromise, unauthorized actions, credential abuse, and unauthorized access
  • Implements filters to analyze anomalies and identify security events
  • Monitors detection tools for effective operation

Implementation notes

CC7.2 expects you to monitor system components for anomalies and analyze whether those anomalies are security events. In SaaS practice, centralize auth, cloud control-plane, application, and infrastructure logs into a SIEM or equivalent, define detection use cases for credential abuse, privilege escalation, unusual data access, and perimeter anomalies, and assign on-call ownership for triage. Filter and summarize noise so analysts can identify true security events. Also monitor the monitors: alert when agents stop reporting or log volume drops to zero. Retain logs long enough to support investigations and Type II sampling. Pair CC7.2 with CC7.3 so analyzed events feed a clear path into incident classification.

Audit tip: Pick two or three closed alerts from the period that show anomaly → analysis → security-event decision, plus proof that key log sources stayed connected.

Evidence auditors typically request:

  • SIEM or centralized logging architecture diagram and retention settings
  • Alert rule catalog with owners and severity
  • Sample security alerts with triage notes from the observation period
  • On-call / detection tool health checks (failed agent or silent source monitoring)
  • Security monitoring policy or SOC runbook

Common gaps

  • Logs collected but never reviewed or alerted — storage without detection
  • Critical production sources (IdP, cloud audit, Kubernetes API) missing from the pipeline
  • Alert fatigue with no documented tuning or ownership
  • No process to verify detection tools themselves are healthy

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC7.2This control
ISO 27001A.8.15, A.8.16Logging and monitoring activities
HIPAA164.312(b), 164.308(a)(1)(ii)(D)Audit controls and information system activity review
GDPRArticle 32(1)Security of processing — monitoring measures

Primary sources

Frequently Asked Questions

AICPA does not mandate a specific product. You need detection tools and procedures that identify and analyze anomalies. Many SaaS teams use a SIEM or cloud-native security analytics; the evidence is coverage, alerts, and triage — not the brand name.

CC7.1 focuses on detecting vulnerabilities and configuration weaknesses. CC7.2 focuses on monitoring runtime behavior of system components for anomalies that may indicate malicious acts, errors, or disasters, then analyzing those anomalies as potential security events.

Criteria require monitoring and analysis appropriate to objectives — not a prescribed staffing model. Document on-call coverage, escalation SLAs, and how after-hours alerts are handled. Gaps in response time often show up under later CC7 incident criteria.

Typically IdP/SSO, cloud provider audit logs, production Kubernetes or host logs, application auth/admin actions, and database or object-storage access for customer data paths. Map sources to the system description population.

HIPAA §164.312(b) and activity review expectations often overlap with logging and monitoring evidence used for CC7.2, but HIPAA has its own required/addressable documentation. Use a crosswalk; do not treat SOC 2 evidence as automatic HIPAA compliance.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above