System components and operations are monitored for anomalies indicative of malicious acts, natural disasters, and errors, and for security events.
Also written as CC 7.2, TSC CC7.2, SOC2 CC7.2, SOC 2 Type 2 CC7.2.
Anomaly and security event monitoring is one of 5 criteria in the System Operations (CC7) series of the Security (Common Criteria) category. System components and operations are monitored for anomalies indicative of malicious acts, natural disasters, and errors, and for security events. CC7 covers detection and response, so the evidence is operational: monitoring configuration, alert samples, incident tickets with timestamps, and proof that identified issues were actually closed out.
When preparing for a SOC 2 audit against CC7.2, gather artefacts such as:
The Trust Services Criteria set out points of focus that describe what an auditor considers when assessing CC7.2. They are not themselves requirements, but they shape the testing:
What actually gets raised against CC7.2, in rough order of how often it comes up:
CC7.2 is Common Criteria. If you outsource monitoring to an MSSP, their service reports and your own review of them both form part of the evidence, and the auditor may ask for the MSSP own assurance report. Confirm your provider can supply that before you rely on them.
CC7.2 corresponds to the following ISO 27001:2022 Annex A control(s): A.7.4, A.8.15, A.8.16, A.8.17. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC7.2 rather than duplicating work.
All CC7 System Operations criteria →
Yes. CC7.2 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC7.2 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.
Yes — CC7.2 aligns with ISO 27001:2022 Annex A control(s) A.7.4, A.8.15, A.8.16, A.8.17. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.
Log retention shorter than the audit period, making early-period sampling impossible. Alerts with no triage record, particularly in the first months of the period before the audit was front of mind.