Skip to main content

๐Ÿ’ผ CC7.4 The entity responds to identified security incidents by executing a defined incident-response program to understand, contain, remediate, and communicate security incidents, as appropriate.

  • Contextual name: ๐Ÿ’ผ CC7.4 The entity responds to identified security incidents by executing a defined incident-response program to understand, contain, remediate, and communicate security incidents, as appropriate.

  • ID: /frameworks/soc-2/cc7/04

  • Located in: ๐Ÿ’ผ CC7 System Operations

Descriptionโ€‹

Empty...

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ CC7.4-1 Assigns Roles and Responsibilities
๐Ÿ’ผ CC7.4-2 Contains and Responds to Security Incidents
๐Ÿ’ผ CC7.4-3 Mitigates Ongoing Security Incidents
๐Ÿ’ผ CC7.4-4 Resolves Security Incidents
๐Ÿ’ผ CC7.4-5 Restores Operations
๐Ÿ’ผ CC7.4-6 Develops and Implements Communication Protocols for Security Incidents
๐Ÿ’ผ CC7.4-7 Obtains Understanding of Nature of Incident and Determines Containment Strategy
๐Ÿ’ผ CC7.4-8 Remediates Identified Vulnerabilities
๐Ÿ’ผ CC7.4-9 Communicates Remediation Activities
๐Ÿ’ผ CC7.4-10 Evaluates the Effectiveness of Incident Response
๐Ÿ’ผ CC7.4-11 Periodically Evaluates Incidents
๐Ÿ’ผ CC7.4-12 Applies Breach Response Procedures
๐Ÿ’ผ CC7.4-13 Communicates Unauthorized Use and Disclosure
๐Ÿ’ผ CC7.4-14 Application of Sanctions