cc7.2-2-001

CC7.2 · D2 · detection_only

D2
Difficulty
4
Gaps
0
Red Herrings
58%
Avg Score

Task

Review the incident response plan for Pinnacle SaaS Inc. and assess whether it adequately addresses SOC 2 CC7.2 requirements for monitoring and anomaly detection. Identify any gaps.

Evidence

Findings

IDTypeSeverityFinding
F-001gaphighNo after-hours coverage for P2 incidents
Section 3.2 states on-call SRE responds to P1 alerts 24/7, but P2 alerts only have a 15-minute triage SLA 'during business hours.' P2 incidents include unauthorized access to production — a serious se...
F-002gapmediumVulnerability scan results only reviewed weekly
Section 3.1 shows Qualys vulnerability scan results go to a weekly report. Critical vulnerabilities discovered by a scan would not be triaged for up to 7 days. CC7.2 requires timely detection of anoma...
F-003gapmediumNo database activity monitoring
Section 3.1 lists infrastructure logs, application logs, CloudTrail, endpoint detection, and email security — but no database activity monitoring (DAM). For a SaaS company, the database is the primary...
F-004gaplowAnnual plan testing is insufficient
Section 6 states the IRP is tested annually via tabletop exercise only. SOC 2 auditors increasingly expect more frequent testing (semi-annual) and varied exercise types (tabletop plus simulated incide...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic75%75%25%38%3/412
Opus 4.7Anthropic100%100%33%50%4/412
GPT-5.5OpenAI75%75%33%46%3/49
GPT-4.1OpenAI0%0%0%0%0/45
Haiku 4.5Anthropic100%100%36%53%4/411
GPT-4oOpenAI0%0%0%0%0/44