CC5.1
Selects and Develops Control Activities
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Select and develop control activities that reduce identified risks to acceptable levels and support achievement of objectives.
Points of focus
- Link controls to specific risks and objectives
- Choose preventive and detective activities at appropriate levels
- Consider manual, automated, and entity-level controls together
Implementation notes
Build controls from product threat and reliability scenarios, pair guardrails with telemetry, and define the exact population, frequency, owner, and retained artifact before declaring a control implemented. Operationalize link controls to specific risks and objectives in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain risk-control matrix with control owners and frequencies with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that controls were copied from a generic checklist and have no traceable risk Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample risk-control matrix with control owners and frequencies with dates and named reviewers. Be ready to walk through how you detect and correct: controls were copied from a generic checklist and have no traceable risk
Evidence auditors typically request:
- Risk-control matrix with control owners and frequencies
- Design documentation explaining preventive and detective coverage
- Control test results showing operation across the review period
Common gaps
- Controls were copied from a generic checklist and have no traceable risk
- A single preventive control is trusted without detection when it fails
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC5.1 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus