CC5.2
Technology Controls
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Select and develop general controls over technology that support reliable operation of business-process and system controls.
Points of focus
- Understand dependencies between applications and technology infrastructure
- Establish controls over technology acquisition, development, and maintenance
- Protect technology through security-management processes
Implementation notes
Standardize cloud resources in reviewed infrastructure code, restrict direct console mutation, monitor drift, and include identity, CI/CD, observability, and managed-service dependencies in the control boundary. Operationalize understand dependencies between applications and technology infrastructure in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain cloud architecture and dependency diagrams with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that infrastructure-as-code is reviewed but emergency console changes are not reconciled Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample cloud architecture and dependency diagrams with dates and named reviewers. Be ready to walk through how you detect and correct: infrastructure-as-code is reviewed but emergency console changes are not reconciled
Evidence auditors typically request:
- Cloud architecture and dependency diagrams
- CI/CD protections, branch rules, and infrastructure-as-code review samples
- Patch, configuration, and platform maintenance records
Common gaps
- Infrastructure-as-code is reviewed but emergency console changes are not reconciled
- A critical SaaS workflow relies on an unmanaged integration with no owner
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC5.2 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus