Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC7.4Incident response programSOC 2System Operations

Official Requirement

The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

When an incident is declared, you follow a documented playbook, not improvising. The playbook covers: understand the scope, contain the damage, eradicate the root cause, recover to normal operations, and communicate to affected parties. Auditors will look for evidence that the plan was actually followed during any incidents in the audit period, and that you tested it even if no real incidents occurred.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Incident Response Plan with defined phases and roles

Implementation steps

  1. Write and publish the Incident Response Plan; it must define the IR lifecycle phases, the Security Response Team membership, and the communication chain for P1/P2 incidents
  2. For containment: document how to isolate a compromised host (disable NIC, remove from VLAN, pull from domain) without destroying forensic evidence
  3. For communication: define when customers, regulators, and cyber insurance must be notified, timelines are often legally required (72-hour breach notification under PIPEDA and Law 25)
  4. Conduct a tabletop exercise annually using a realistic scenario (e.g., a server running ransomware); document the exercise, who attended, decisions made, and plan gaps identified

Tools / systems

Evidence artifacts

Evidence frequency: Annual plan review and tabletop exercise; per-incident phase documentation