CC7.4 CC7 · System Operations · Security (Common Criteria)

CC7.4 — Incident response execution

Identified security incidents are responded to through the execution of a defined incident response program.

Also written as CC 7.4, TSC CC7.4, SOC2 CC7.4, SOC 2 Type 2 CC7.4.

What SOC 2 CC7.4 requires

Incident response execution is one of 5 criteria in the System Operations (CC7) series of the Security (Common Criteria) category. Identified security incidents are responded to through the execution of a defined incident response program. CC7 covers detection and response, so the evidence is operational: monitoring configuration, alert samples, incident tickets with timestamps, and proof that identified issues were actually closed out.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC7.4, gather artefacts such as:

  • Incident response plan and playbooks
  • Incident tickets showing containment / eradication steps
  • Communication records during incidents (internal + customer)
  • Tabletop exercise or IR test records

ISO 27001 mapping

CC7.4 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.24, A.5.26, A.5.28. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC7.4 rather than duplicating work.

Map CC7.4 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC7.4 in the Risk Register.

Other System Operations criteria

CC7.1 Vulnerability and configuration monitoring CC7.2 Anomaly and security event monitoring CC7.3 Security event evaluation CC7.5 Incident recovery

All CC7 System Operations criteria →

Frequently asked questions

Is CC7.4 required for a SOC 2 report?

Yes. CC7.4 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC7.4?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC7.4 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC7.4 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.

Does SOC 2 CC7.4 map to ISO 27001?

Yes — CC7.4 aligns with ISO 27001:2022 Annex A control(s) A.5.24, A.5.26, A.5.28. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.