Skip to content
compliancebase
SOC 2CC7 — Evaluation of Security Events

CC7.3

Evaluation of Security Events

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.

Points of focus

  • Responds to security incidents and periodically evaluates the effectiveness of those procedures
  • Communicates and reviews detected security events with individuals responsible for the security program
  • Develops and implements procedures to analyze security incidents and determine system impact

Implementation notes

Under CC7.3, detected security events must be evaluated to decide whether they are security incidents — failures (or potential failures) against entity objectives — and then acted on. Write a severity and classification scheme your on-call can apply in minutes, route events to named security owners, and require a recorded decision: dismiss with rationale, watch, or declare incident and invoke CC7.4 response. Analyze impact on confidentiality, integrity, availability, and (if in scope) privacy. Periodically test that the evaluation procedures still work via tabletop exercises. For Type II, retain the event queue and incident log for the full observation window; 'we had no incidents' still needs evidence that monitoring and evaluation operated.

Audit tip: Provide a sample of triaged alerts with who reviewed them, the classification outcome, and the next action — especially borderline cases that were not promoted to incidents.

Evidence auditors typically request:

  • Incident classification / severity matrix in the IR plan
  • Security event queue tickets showing triage decisions (event vs incident)
  • Meeting or chat escalation records to security owners
  • Periodic IR tabletop or procedure-effectiveness review notes
  • Incident log covering the observation period (including 'no incidents' attestation if true)

Common gaps

  • IR plan exists but no artifacts showing events were evaluated during the period
  • Alerts closed as noise without documented rationale or reviewer identity
  • No clear definition distinguishing security event from security incident
  • Events never communicated to the person accountable for the security program

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC7.3This control
ISO 27001A.5.24, A.5.25Incident management planning and assessment/decision on events
HIPAA164.308(a)(6)(i)Security incident procedures
GDPRArticle 33, Article 32Breach assessment and security of processing

Primary sources

Frequently Asked Questions

In TSC terms, security incidents are security events that could or have resulted in a failure to meet objectives. CC7.3 is the evaluation step that makes that determination and triggers preventive or corrective action.

No. You need operating evaluation procedures. If no events rose to incidents, show the monitoring/triage activity and a period incident log (or management representation supported by the queue) so auditors see the control operated.

Individuals responsible for managing the security program — typically security engineering, a SOC lead, or an on-call engineer with a documented escalation to security leadership. The criterion emphasizes communication and review by those accountable owners.

When the privacy category is in scope, additional points of focus require assessing whether events involved unauthorized use or disclosure of personal information. Even on Security-only exams, GDPR/HIPAA breach assessment may still apply legally — keep IR and privacy playbooks aligned.

At least annually is common; many SaaS teams run tabletop exercises twice a year. Document findings and updates to the plan. CC7.3 explicitly calls out periodic evaluation of response procedures' effectiveness.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above