Skip to main content
Category: Trust Services Criteria

System Operations (CC7)

Also known as: CC7, CC7, System Operations Criteria, Common Criteria 7
Simply put

System Operations, referred to as CC7, is one of the groups of Common Criteria within a SOC 2 examination. It focuses on how an organization watches its systems for problems, spots unusual activity or new vulnerabilities, and responds to and recovers from security incidents. It is part of the Security category, which is the required foundation of any SOC 2 examination.

Formal definition

CC7 (System Operations) is a subset of the Common Criteria that make up the Security category of the AICPA Trust Services Criteria, evaluated within a SOC 2 examination conducted by a licensed CPA firm under SSAE 18. Based on the evidence provided, CC7 spans a series of criteria (CC7.1 through CC7.5) addressing operational activities such as procedures for monitoring changes to configurations (CC7.1), continuous monitoring of operational data to detect anomalies and new vulnerabilities (CC7.2), and the identification, development, and implementation of activities to recover from identified security incidents, including system rebuilds, patch management, critical updates, and access revocation (CC7.5). Because Security is the only required Trust Services category, CC7 is in scope for essentially all SOC 2 engagements, whereas the optional categories (Availability, Processing Integrity, Confidentiality, Privacy) are selected based on scope. The specific controls mapped to each CC7 criterion, and how their design and operating effectiveness are assessed, depend on the service organization's environment and the scoping decisions of the engagement; a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches. Note that CC7 is distinct from ISO 27001 requirements and Annex A controls, and satisfying CC7 does not automatically satisfy any ISO 27001 requirement.

Why it matters

System Operations (CC7) addresses the operational core of an organization's security posture: the ability to detect that something has gone wrong and to respond and recover when it does. Within a SOC 2 examination, the Security category (the Common Criteria) is the only required Trust Services category, so CC7 is in scope for essentially all SOC 2 engagements. This makes it one of the areas most consistently scrutinized by the licensed CPA firm conducting the examination.

The practical significance of CC7 lies in its focus on the moments when preventive controls fail. Detection of anomalies and new vulnerabilities (CC7.1 and CC7.2) determines whether an organization notices a problem at all, while incident recovery activities (CC7.5), including system rebuilds, patch management, critical updates, and access revocation, determine how quickly and completely it can restore a secure state. Weaknesses in these areas often surface as findings in a SOC 2 report because they represent the difference between a contained event and an extended compromise.

It is important to keep the boundaries clear: a SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches. Strong CC7 controls demonstrate that monitoring and response processes were suitably designed and, in a Type II engagement, operating effectively over the review period, but they are not a warranty against future incidents. CC7 is also distinct from ISO 27001 requirements and Annex A controls; satisfying CC7 does not automatically satisfy any ISO 27001 requirement.

Who it's relevant to

Security engineers and operations teams
These teams own the monitoring, detection, and recovery activities that CC7 evaluates, configuration change monitoring, anomaly and vulnerability detection, patch management, and incident recovery. In most engagements they are responsible for producing the operational evidence that demonstrates these controls were designed and, for a Type II examination, operating effectively over the review period.
Compliance and GRC managers
Because Security is the required foundation of any SOC 2 examination, CC7 is in scope for essentially all engagements. GRC professionals coordinate the mapping of internal controls to the CC7 criteria, manage supplier and vendor documentation where relevant to configuration monitoring, and help set the scope that determines how CC7 is assessed.
SOC 2 auditors
The licensed CPA firm conducting the examination under SSAE 18 evaluates the controls mapped to CC7 for suitability of design and, in a Type II engagement, operating effectiveness. Their scoping decisions influence which controls are tested and how, and their report attests only to the controls and period covered.
Incident response and recovery stakeholders
CC7.5 specifically concerns recovery from identified security incidents, including system rebuilds, patch management, critical updates, and access revocation. Teams accountable for incident response benefit from aligning their playbooks and documentation with these criteria, while recognizing that CC7 does not guarantee freedom from breaches.

Inside CC7

Detection and Monitoring of Anomalies
Controls within CC7 typically address the use of detection tools, monitoring processes, and configuration baselines to identify anomalies, vulnerabilities, and potential security events across the system environment. The specific tooling and thresholds vary depending on scope and the auditor's evaluation.
Security Event Evaluation and Response
This component generally covers how identified events are analyzed, triaged, and escalated to determine whether they constitute a security incident, as well as the procedures for responding to and containing confirmed incidents. The exact response workflows depend on the entity's design decisions.
Incident Recovery and Remediation
CC7 typically includes controls for recovering from identified security incidents and remediating underlying weaknesses, including communication and post-incident activities. What qualifies as adequate recovery is assessed relative to the controls the entity has defined.
Part of the Common Criteria (Security)
CC7 is one of the Common Criteria control series that make up the Security category, which is the only required Trust Services Criteria category in a SOC 2 examination. It is evaluated by a licensed CPA firm under the AICPA SSAE 18 standard and should not be confused with ISO 27001 Annex A controls.

Common questions

Answers to the questions practitioners most commonly ask about CC7.

Does implementing the CC7 System Operations criteria mean my organization is protected against all security breaches?
No. CC7 addresses controls for detecting, monitoring, and responding to anomalies, security events, and incidents, but a SOC 2 report attests only to the controls in scope and their operation over the period covered. It does not guarantee freedom from breaches. The criteria focus on whether an organization has designed and, in a Type II examination, operated processes to identify and respond to issues, not on eliminating the possibility of an incident occurring.
Are the CC7 System Operations criteria the same as the ISO 27001 Annex A controls covering operations and incident management?
No. CC7 is part of the Trust Services Criteria's Common Criteria used in a SOC 2 examination, while Annex A lists reference controls under ISO/IEC 27001, selected via a Statement of Applicability. The two can be mapped in part, but the mapping is partial, and satisfying CC7 does not automatically satisfy the corresponding Annex A controls or the ISMS requirements in clauses 4 through 10. They are distinct frameworks with different structures and evaluation approaches.
What kinds of activities does CC7 typically cover in a SOC 2 examination?
CC7 typically addresses system operations activities such as detecting and monitoring for anomalies and vulnerabilities, evaluating and responding to security events, and managing incidents through identification, containment, remediation, and recovery. The specific controls in scope depend on the organization's environment and the scoping decisions made for the engagement, so the activities examined can vary.
How does a Type I examination differ from a Type II examination with respect to CC7?
In a Type I examination, the auditor assesses the suitability of the design of CC7 controls at a point in time. In a Type II examination, the auditor assesses both the design and the operating effectiveness of those controls over a defined review period. The length of that period varies and is set by scoping decisions rather than being fixed.
What types of evidence are commonly relied upon to demonstrate CC7 controls in a Type II examination?
In most engagements, evidence for CC7 may include monitoring and alerting records, vulnerability scan or assessment outputs, incident tickets and response documentation, and records showing evaluation and resolution of security events over the review period. The exact evidence expected depends on the auditor, the scope, and how the controls are designed, so organizations should confirm expectations with their examining CPA firm.
Is a formal incident response process required to satisfy CC7?
The Trust Services Criteria contemplate that an organization detects, responds to, and recovers from security events and incidents, so in most engagements auditors expect some documented and operating process for handling incidents. However, the specific form that process takes depends on the organization, its environment, and the auditor's evaluation, so it is best characterized as an expectation shaped by scope rather than a single prescribed approach.

Common misconceptions

Meeting CC7 in a SOC 2 report means the organization is guaranteed not to experience a security breach.
A SOC 2 report attests only to the design (Type I) or the design and operating effectiveness (Type II) of the controls over the period and scope covered. It does not guarantee freedom from breaches, and CC7 controls address detection and response capabilities rather than eliminating all risk of an incident.
CC7 controls are equivalent to, and satisfying them fulfills, the corresponding ISO 27001 operational or incident management requirements.
CC7 belongs to the SOC 2 Trust Services Criteria evaluated in a CPA attestation, whereas ISO 27001 is a certification against an ISMS management system standard with requirements in clauses 4 through 10 and reference controls in Annex A. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other.
A single prescribed set of monitoring tools or response steps is mandatory to meet CC7.
The criteria describe objectives for detection, evaluation, response, and recovery, but the specific tooling, thresholds, and procedures are determined by the entity's scope and design decisions and evaluated by the auditor. No single control or approach is universally mandated.

Best practices

Define and document detection and monitoring processes, including configuration baselines and thresholds, so that anomalies and potential security events can be consistently identified within the defined scope.
Establish clear procedures for evaluating, triaging, and escalating identified events to determine whether they represent security incidents, and assign responsibility for these decisions.
Maintain documented incident response and recovery procedures, and retain evidence of their execution so that operating effectiveness can be demonstrated in a Type II examination over the review period.
For a SOC 2 Type II, ensure monitoring and response activities generate consistent evidence throughout the entire review period, since the period length is set by scoping decisions rather than a fixed duration.
Where the organization also pursues ISO 27001, map CC7 activities to the relevant ISMS operational and incident-related requirements deliberately, recognizing the mapping is partial and each framework must be satisfied on its own terms.
Conduct post-incident reviews to remediate underlying weaknesses and feed lessons learned back into detection and response controls, depending on the scope defined for the engagement.