Skip to content

Latest commit

 

History

History
27 lines (27 loc) · 2.72 KB

cc75.md

File metadata and controls

27 lines (27 loc) · 2.72 KB

SOC2 - CC7.5

The entity identifies, develops, and implements activities to recover from identified security incidents

Restores the Affected Environment

The activities restore the affected environment to functional operation by rebuilding systems, updating software, installing patches, and changing configurations, as needed

Communicates Information About the Event

Communications about the nature of the incident, recovery actions taken, and activities required for the prevention of future security events are made to management and others as appropriate (internal and external)

Determines Root Cause of the Event

The root cause of the event is determined

Implements Changes to Prevent and Detect Recurrences

Additional architecture or changes to preventive and detective controls, or both, are implemented to prevent and detect recurrences on a timely basis

Improves Response and Recovery Procedures

Lessons learned are analyzed, and the incident response plan and recovery procedures are improved

Implements Incident Recovery Plan Testing

Incident recovery plan testing is performed on a periodic basis. The testing includes (1) development of testing scenarios based on threat likelihood and magnitude; (2) consideration of relevant system components from across the entity that can impair availability; (3) scenarios that consider the potential for the lack of availability of key personnel; and (4) revision of continuity plans and systems based on test results..

Mapped SCF controls