{
  "node_id": "soc2-cc7-system-operations",
  "title": "AICPA SOC 2 Common Criteria CC7 - System Operations (CC7.1-CC7.5)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "CC7 is the System Operations series of the SOC 2 Common Criteria (CC7.1-CC7.5). It requires the entity to use detection and monitoring procedures to identify configuration changes and vulnerabilities, to monitor system components for anomalies, to evaluate security events to determine whether they constitute incidents, to respond to identified incidents through a defined incident-response program, and to identify, develop, and implement recovery activities. CC7 operationalizes detection, response, and recovery.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 6
}