CC7 Security Required

System Operations

Complete guide to CC7 System Operations controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

5 Controls
3 Critical
2 High
CC7.1 critical

Vulnerability Detection

You run regular vulnerability scans on your infrastructure and application. Findings are triaged, tracked, and remediated within defined SLAs (e.g., critical = 24h, high = 7 days).

View official AICPA language

To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations or the environment.

What auditors look for

Quarterly vulnerability scan reports, vulnerability tracker showing remediation timelines, CVSS severity-based SLA policy

CC7.2 critical

Security Incident Response

You have a Security Incident Response Plan (SIRP) and actually used it (or tested it) during the audit period. Security events are logged, alerts are configured, and there is an on-call rotation.

View official AICPA language

The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives.

What auditors look for

Security Incident Response Plan (dated), incident response tabletop exercise records, SIEM alert configuration, on-call schedule

CC7.3 critical

Incident Response Execution

When a security event occurs, you follow your SIRP: classify the event, contain it, investigate, remediate, and document a post-incident review. Stakeholders are notified appropriately.

View official AICPA language

The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives.

What auditors look for

Post-incident review reports, incident tickets showing classification, containment actions, and root cause analysis

CC7.4 high

Incident Response — Recovery

After a security incident, you restore affected systems to their prior state, verify data integrity, and communicate with affected parties within contractually or legally required timeframes.

View official AICPA language

The entity responds to identified security incidents by executing a defined incident response program.

What auditors look for

Recovery runbooks, backup restoration test records, customer notification templates and logs, DR test results

CC7.5 high

Disclosure to Affected Parties

You have a documented process for notifying affected customers and regulatory bodies after a security incident. Notification timelines comply with GDPR, CCPA, or contract requirements.

View official AICPA language

The entity identifies, develops, and implements activities to recover from identified security incidents.

What auditors look for

Breach notification policy, example notification templates, documented stakeholder communication list

Track all 5 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today