CC7.3
Evaluation of Security Events
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.
Points of focus
- Responds to security incidents and periodically evaluates the effectiveness of those procedures
- Communicates and reviews detected security events with individuals responsible for the security program
- Develops and implements procedures to analyze security incidents and determine system impact
Implementation notes
Under CC7.3, detected security events must be evaluated to decide whether they are security incidents — failures (or potential failures) against entity objectives — and then acted on. Write a severity and classification scheme your on-call can apply in minutes, route events to named security owners, and require a recorded decision: dismiss with rationale, watch, or declare incident and invoke CC7.4 response. Analyze impact on confidentiality, integrity, availability, and (if in scope) privacy. Periodically test that the evaluation procedures still work via tabletop exercises. For Type II, retain the event queue and incident log for the full observation window; 'we had no incidents' still needs evidence that monitoring and evaluation operated.
Audit tip: Provide a sample of triaged alerts with who reviewed them, the classification outcome, and the next action — especially borderline cases that were not promoted to incidents.
Evidence auditors typically request:
- Incident classification / severity matrix in the IR plan
- Security event queue tickets showing triage decisions (event vs incident)
- Meeting or chat escalation records to security owners
- Periodic IR tabletop or procedure-effectiveness review notes
- Incident log covering the observation period (including 'no incidents' attestation if true)
Common gaps
- IR plan exists but no artifacts showing events were evaluated during the period
- Alerts closed as noise without documented rationale or reviewer identity
- No clear definition distinguishing security event from security incident
- Events never communicated to the person accountable for the security program
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC7.3 | This control |
| ISO 27001 | A.5.24, A.5.25 | Incident management planning and assessment/decision on events |
| HIPAA | 164.308(a)(6)(i) | Security incident procedures |
| GDPR | Article 33, Article 32 | Breach assessment and security of processing |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus