Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
33 controls
CC1.1
Commitment to integrity and ethical values
Control Environment
6 evidence2 controls
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2Monitoring for anomalies and security eventsSOC 2System Operations
Official Requirement
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.
Your SIEM or monitoring stack ingests logs from all relevant systems, servers, network devices, identity providers, and has detection rules that surface anomalies worth investigating. Finding an anomaly isn't enough; you need a documented process for triaging it and deciding whether it rises to a security event. Auditors will ask to see alerts that fired AND evidence they were reviewed.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control SIEM with centralized log aggregation and alert triage
Build detection rules for high-signal anomalies: impossible travel logins, brute-force patterns, privilege escalation, mass data download, and after-hours admin activity
Route all medium and high severity alerts to your alerting/on-call platform or the security team Slack channel with an SLA for initial triage (e.g., critical: 15 min, high: 4 hours)
Document the triage process: each alert gets a ticket, an analyst notes their assessment, and the ticket closes with a disposition (true positive, false positive, or escalated)
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
SIEM with centralized log aggregation and alert triage
Implementation steps
Configure your SIEM/monitoring platform to ingest logs from all production servers, the firewall appliance (syslog), your IDS/network monitoring platform (IDS alerts), and Active Directory event logs
Enable your SIEM/monitoring platform's built-in detection rules for authentication failures, privilege escalation, rootkit indicators, and web attack patterns; tune false positives by creating custom rule exclusions
Set up your SIEM/monitoring platform email or webhook alerts for high-severity rules; the ISM must review and disposition each alert within a defined SLA
Maintain a Security Monitoring Log: a running record of alerts reviewed, triage notes, and outcome, this is the primary audit artifact for CC7.2
Tools / systems
Wazuh (SIEM + detection)
Security Onion (network IDS)
Firewall appliance (syslog source)
Active Directory (Windows event logs)
Nagios/Zabbix (availability monitoring)
Evidence artifacts
Wazuh dashboard screenshot showing active agents and alert count for the audit period
Security Monitoring Log export showing 3-5 sample alerts reviewed and dispositioned during the audit period
Wazuh alert rule configuration screenshot confirming high-severity rules are active
Evidence that syslog from the firewall appliance and AD event logs are reaching Wazuh (source health screenshot)
Evidence frequency: Continuous ingestion; ISM reviews alerts daily; Security Monitoring Log updated per alert