SOC 2_CC7.5

SOC 2

Security System Operations

CC7.5

The entity identifies develops and implements activities to recover from identified security incidents.

Restores the Affected Environment—The activities restore the affected environment to functional operation by rebuilding systems updating software installing patches and changing configurations as needed. Communicates Information About the Event—Communications about the nature of the incident recovery actions taken and activities required for the prevention of future security events are made to management and others as appropriate (internal and external). Determines Root Cause of the Event—The root cause of the event is determined. Implements Changes to Prevent and Detect Recurrences—Additional architecture or changes to preventive and detective controls or both are implemented to prevent and detect recurrences on a timely basis. Improves Response and Recovery Procedures—Lessons learned are analyzed and the incident response plan and recovery procedures are improved. Implements Incident Recovery Plan Testing—Incident recovery plan testing is performed on a periodic basis. The testing includes (1) development of testing scenarios based on threat likelihood and magnitude; (2) consideration of relevant system components from across the entity that can impair availability; (3) scenarios that consider the potential for the lack of availability of key personnel; and (4) revision of continuity plans and systems based on test results.

 

Click here to Start your FREE trial today!

Explainer video

 

What is a Cybersecurity Compliance Framework?

You don’t need to clutter your security and privacy programs with an ever-increasing number of tools as they become more sophisticated. The Lionfish platform offers a one-stop solution to track progress and monitor any framework, from custom-built ones to highly-specialized and in-demand top security and privacy frameworks and certifications.

With the Lionfish platform, every framework is supported with guided scoping, policies, controls, automated evidence collection, and continuous monitoring, ensuring efficient preparation for audits or attestation in minimal time.

The Lionfish platform is compatible with a wide range of security and privacy frameworks, including:

Click here to Start your FREE trial today!

Explainer video