System Operations
Complete guide to CC7 System Operations controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
Vulnerability Detection
Plain English
You run regular vulnerability scans on your infrastructure and application. Findings are triaged, tracked, and remediated within defined SLAs (e.g., critical = 24h, high = 7 days).
View official AICPA language
To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations or the environment.
What auditors look for
Quarterly vulnerability scan reports, vulnerability tracker showing remediation timelines, CVSS severity-based SLA policy
Security Incident Response
Plain English
You have a Security Incident Response Plan (SIRP) and actually used it (or tested it) during the audit period. Security events are logged, alerts are configured, and there is an on-call rotation.
View official AICPA language
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives.
What auditors look for
Security Incident Response Plan (dated), incident response tabletop exercise records, SIEM alert configuration, on-call schedule
Incident Response Execution
Plain English
When a security event occurs, you follow your SIRP: classify the event, contain it, investigate, remediate, and document a post-incident review. Stakeholders are notified appropriately.
View official AICPA language
The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives.
What auditors look for
Post-incident review reports, incident tickets showing classification, containment actions, and root cause analysis
Incident Response — Recovery
Plain English
After a security incident, you restore affected systems to their prior state, verify data integrity, and communicate with affected parties within contractually or legally required timeframes.
View official AICPA language
The entity responds to identified security incidents by executing a defined incident response program.
What auditors look for
Recovery runbooks, backup restoration test records, customer notification templates and logs, DR test results
Disclosure to Affected Parties
Plain English
You have a documented process for notifying affected customers and regulatory bodies after a security incident. Notification timelines comply with GDPR, CCPA, or contract requirements.
View official AICPA language
The entity identifies, develops, and implements activities to recover from identified security incidents.
What auditors look for
Breach notification policy, example notification templates, documented stakeholder communication list
Track all 5 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today