Skip to content
compliancebase
SOC 2CC7 — Response to Security Incidents

CC7.4

Response to Security Incidents

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity responds to identified security incidents by executing a defined incident-response program to understand, contain, remediate, and communicate security incidents, as appropriate.

Points of focus

  • Assigns roles and responsibilities for the incident-response program, including external resources when needed
  • Contains security incidents that threaten entity objectives
  • Mitigates effects of ongoing security incidents
  • Ends threats by closing vulnerabilities, removing unauthorized access, and other remediation
  • Restores operations to an interim state that permits achievement of objectives
  • Develops and implements communication protocols for security incidents
  • Obtains understanding of nature and severity to determine containment strategy
  • Remediates identified vulnerabilities and communicates remediation activities
  • Evaluates effectiveness of incident response periodically and reviews incident patterns

Implementation notes

CC7.4 requires a defined incident-response program that is actually executed: understand the incident, contain it, remediate, and communicate as appropriate. For SaaS, publish a living IR plan with severity definitions, incident commander and communications roles, pager escalation, evidence preservation steps, and customer/status-page protocols. Practice containment playbooks for credential compromise, ransomware-like encryption events, and production data exposure. Document every material incident in a ticket with timeline, decisions, and remediation owners. Align notification clocks with GDPR Article 33 and contractual SLA language so legal and security share one clock. Periodically review incidents for patterns and improve the program — that continuous improvement is part of the criterion's points of focus.

Audit tip: Walk one incident end-to-end: detection time, commander, containment actions, communications, and remediation tickets — timestamps matter.

Evidence auditors typically request:

  • Incident response plan with roles, severity levels, and communication matrix
  • Completed incident tickets showing contain → eradicate → recover steps
  • Customer or regulator notification templates and send records when applicable
  • Post-incident remediation tickets linked to root cause
  • Tabletop exercise report if few live incidents occurred

Common gaps

  • IR plan on a wiki with no evidence of execution during the observation window
  • No named incident commander or on-call roles
  • Containment actions taken but never documented
  • Customer-impacting incidents without a communication decision record

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC7.4This control
ISO 27001A.5.26, A.5.24Response to information security incidents
HIPAA164.308(a)(6)(ii)Response and reporting of security incidents
GDPRArticle 33, Article 34Breach notification to authority and data subjects when required

Primary sources

Frequently Asked Questions

Tabletops help prove design and readiness, especially when the period had no live incidents. If incidents did occur, auditors expect execution artifacts for those events. Best practice is both: live handling evidence when available and periodic exercises.

At minimum: incident commander, technical lead, communications owner, and executive sponsor. Include when to engage external forensics or counsel. CC7.4 points of focus explicitly call out assigned roles and external resources when necessary.

TSC does not prescribe a universal clock; your severity matrix should. Capture detection-to-containment times in tickets. Slow containment without documented blockers often becomes an audit discussion point and a customer-trust issue.

Communicate as appropriate to meet objectives and legal/contractual duties. Not every security incident is a notifiable breach. Record the notification decision with legal input so CC7.4 communications and GDPR/HIPAA analyses stay consistent.

CC7.4 is the response program during an active incident (understand, contain, remediate, communicate). CC7.5 focuses on recovery activities afterward: restoring the environment, root cause, preventive changes, and recovery-plan testing.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above