CC7.4
Response to Security Incidents
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity responds to identified security incidents by executing a defined incident-response program to understand, contain, remediate, and communicate security incidents, as appropriate.
Points of focus
- Assigns roles and responsibilities for the incident-response program, including external resources when needed
- Contains security incidents that threaten entity objectives
- Mitigates effects of ongoing security incidents
- Ends threats by closing vulnerabilities, removing unauthorized access, and other remediation
- Restores operations to an interim state that permits achievement of objectives
- Develops and implements communication protocols for security incidents
- Obtains understanding of nature and severity to determine containment strategy
- Remediates identified vulnerabilities and communicates remediation activities
- Evaluates effectiveness of incident response periodically and reviews incident patterns
Implementation notes
CC7.4 requires a defined incident-response program that is actually executed: understand the incident, contain it, remediate, and communicate as appropriate. For SaaS, publish a living IR plan with severity definitions, incident commander and communications roles, pager escalation, evidence preservation steps, and customer/status-page protocols. Practice containment playbooks for credential compromise, ransomware-like encryption events, and production data exposure. Document every material incident in a ticket with timeline, decisions, and remediation owners. Align notification clocks with GDPR Article 33 and contractual SLA language so legal and security share one clock. Periodically review incidents for patterns and improve the program — that continuous improvement is part of the criterion's points of focus.
Audit tip: Walk one incident end-to-end: detection time, commander, containment actions, communications, and remediation tickets — timestamps matter.
Evidence auditors typically request:
- Incident response plan with roles, severity levels, and communication matrix
- Completed incident tickets showing contain → eradicate → recover steps
- Customer or regulator notification templates and send records when applicable
- Post-incident remediation tickets linked to root cause
- Tabletop exercise report if few live incidents occurred
Common gaps
- IR plan on a wiki with no evidence of execution during the observation window
- No named incident commander or on-call roles
- Containment actions taken but never documented
- Customer-impacting incidents without a communication decision record
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC7.4 | This control |
| ISO 27001 | A.5.26, A.5.24 | Response to information security incidents |
| HIPAA | 164.308(a)(6)(ii) | Response and reporting of security incidents |
| GDPR | Article 33, Article 34 | Breach notification to authority and data subjects when required |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus