Skip to content
compliancebase
SOC 2CC5 — Selects and Develops Control Activities

CC5.1

Selects and Develops Control Activities

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Select and develop control activities that reduce identified risks to acceptable levels and support achievement of objectives.

Points of focus

  • Link controls to specific risks and objectives
  • Choose preventive and detective activities at appropriate levels
  • Consider manual, automated, and entity-level controls together

Implementation notes

Build controls from product threat and reliability scenarios, pair guardrails with telemetry, and define the exact population, frequency, owner, and retained artifact before declaring a control implemented. Operationalize link controls to specific risks and objectives in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain risk-control matrix with control owners and frequencies with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that controls were copied from a generic checklist and have no traceable risk Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample risk-control matrix with control owners and frequencies with dates and named reviewers. Be ready to walk through how you detect and correct: controls were copied from a generic checklist and have no traceable risk

Evidence auditors typically request:

  • Risk-control matrix with control owners and frequencies
  • Design documentation explaining preventive and detective coverage
  • Control test results showing operation across the review period

Common gaps

  • Controls were copied from a generic checklist and have no traceable risk
  • A single preventive control is trusted without detection when it fails

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC5.1This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Selects and Develops Control Activities applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — link controls to specific risks and objectives — with evidence stored where auditors and customers can sample it.

Lead with risk-control matrix with control owners and frequencies and pair it with design documentation explaining preventive and detective coverage. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because controls were copied from a generic checklist and have no traceable risk Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above