Control cross-reference
SOC 2 and your incident response exercise.
SOC 2 auditors ask how you respond to incidents and how you know the response works. The criteria below are the ones an incident response exercise speaks to.
This is a cross-reference, not an assessment. Running an exercise does not by itself satisfy any control here. It produces a dated, attributed record, and your auditor decides what that record is worth against these criteria.
The controls
What an exercise speaks to.
-
CC7.4
Incident response
-
CC7.5
Recovery from identified security incidents
-
CC9.2
Vendor and business partner risk
-
A1.3
Testing of recovery plan procedures
The evidence
What a reviewer is actually asking for.
Not the plan. Almost everyone has a plan. They are asking whether it was exercised, when, by whom, and what that surfaced. That is a record with a date and people in it, and it only exists if the exercise actually happened.
Run one.
A live tabletop on your own systems and plan, with the record written by the time you finish, for $199.