System Operations (CC7)
System Operations, referred to as CC7, is one of the groups of Common Criteria within a SOC 2 examination. It focuses on how an organization watches its systems for problems, spots unusual activity or new vulnerabilities, and responds to and recovers from security incidents. It is part of the Security category, which is the required foundation of any SOC 2 examination.
CC7 (System Operations) is a subset of the Common Criteria that make up the Security category of the AICPA Trust Services Criteria, evaluated within a SOC 2 examination conducted by a licensed CPA firm under SSAE 18. Based on the evidence provided, CC7 spans a series of criteria (CC7.1 through CC7.5) addressing operational activities such as procedures for monitoring changes to configurations (CC7.1), continuous monitoring of operational data to detect anomalies and new vulnerabilities (CC7.2), and the identification, development, and implementation of activities to recover from identified security incidents, including system rebuilds, patch management, critical updates, and access revocation (CC7.5). Because Security is the only required Trust Services category, CC7 is in scope for essentially all SOC 2 engagements, whereas the optional categories (Availability, Processing Integrity, Confidentiality, Privacy) are selected based on scope. The specific controls mapped to each CC7 criterion, and how their design and operating effectiveness are assessed, depend on the service organization's environment and the scoping decisions of the engagement; a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches. Note that CC7 is distinct from ISO 27001 requirements and Annex A controls, and satisfying CC7 does not automatically satisfy any ISO 27001 requirement.
Why it matters
System Operations (CC7) addresses the operational core of an organization's security posture: the ability to detect that something has gone wrong and to respond and recover when it does. Within a SOC 2 examination, the Security category (the Common Criteria) is the only required Trust Services category, so CC7 is in scope for essentially all SOC 2 engagements. This makes it one of the areas most consistently scrutinized by the licensed CPA firm conducting the examination.
The practical significance of CC7 lies in its focus on the moments when preventive controls fail. Detection of anomalies and new vulnerabilities (CC7.1 and CC7.2) determines whether an organization notices a problem at all, while incident recovery activities (CC7.5), including system rebuilds, patch management, critical updates, and access revocation, determine how quickly and completely it can restore a secure state. Weaknesses in these areas often surface as findings in a SOC 2 report because they represent the difference between a contained event and an extended compromise.
It is important to keep the boundaries clear: a SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches. Strong CC7 controls demonstrate that monitoring and response processes were suitably designed and, in a Type II engagement, operating effectively over the review period, but they are not a warranty against future incidents. CC7 is also distinct from ISO 27001 requirements and Annex A controls; satisfying CC7 does not automatically satisfy any ISO 27001 requirement.
Who it's relevant to
Inside CC7
Common questions
Answers to the questions practitioners most commonly ask about CC7.