Skip to content
compliancebase
SOC 2CC5 — Technology Controls

CC5.2

Technology Controls

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Select and develop general controls over technology that support reliable operation of business-process and system controls.

Points of focus

  • Understand dependencies between applications and technology infrastructure
  • Establish controls over technology acquisition, development, and maintenance
  • Protect technology through security-management processes

Implementation notes

Standardize cloud resources in reviewed infrastructure code, restrict direct console mutation, monitor drift, and include identity, CI/CD, observability, and managed-service dependencies in the control boundary. Operationalize understand dependencies between applications and technology infrastructure in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain cloud architecture and dependency diagrams with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that infrastructure-as-code is reviewed but emergency console changes are not reconciled Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample cloud architecture and dependency diagrams with dates and named reviewers. Be ready to walk through how you detect and correct: infrastructure-as-code is reviewed but emergency console changes are not reconciled

Evidence auditors typically request:

  • Cloud architecture and dependency diagrams
  • CI/CD protections, branch rules, and infrastructure-as-code review samples
  • Patch, configuration, and platform maintenance records

Common gaps

  • Infrastructure-as-code is reviewed but emergency console changes are not reconciled
  • A critical SaaS workflow relies on an unmanaged integration with no owner

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC5.2This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Technology Controls applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — understand dependencies between applications and technology infrastructure — with evidence stored where auditors and customers can sample it.

Lead with cloud architecture and dependency diagrams and pair it with ci/cd protections, branch rules, and infrastructure-as-code review samples. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because infrastructure-as-code is reviewed but emergency console changes are not reconciled Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above