August 30, 2023

SOC 2 Controls CC5: Control Activities

The fifth SOC-2 requirement in the CC-series is Control Activities.

By
Full name
Share this post
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

CC5.1

SOC 2 CC5.1 requires that your organisation selects and develops control activities that contribute to mitigating risks to achieving objectives to acceptable levels.

CC5.1 highlights the following points of focus:

Integrates With Risk Assessment

Your organisation’s control activities should help ensure that risk responses that both address and alleviate risks are undertaken.

Considers Organisation-Specific Factors

The management team should consider how the environment, complexity, nature, and scope of its operations, as well as the specific attributes of the organisation, impact the selection and progression of control activities.

Determines Appropriate Business Processes

Your management team should determine which relevant business procedures require control activities.

Considers a Mix of Control Activity Types

Your organisation’s control activities should include a range of controls and a balance of approaches to mitigate risks. This may include considering both manual and automated controls and preventive and detective controls.

Considers at What Level Activities Are Applied

The management team should consider control activities at multiple levels in the organisation.

Addresses Segregation of Duties

Your management team should separate incompatible duties, and where such separation is not practical, management should select and develop alternate control activities.

CC5.2

SOC 2 CC5.2 requires that your organisation selects and develops general control activities over technology to support achieving objectives.

CC5.2 highlights the following points of focus:

Determines Reliance Between the Use of Technology in Business Processes and Technology General Controls

The management team should understand and establish the dependency and connection between business processes, automated control activities, and general technology controls.

Determines Relevant Technology Infrastructure Control Activities

Management should select and develop control activities over the technology infrastructure. These control activities should be designed and implemented to help ensure the completeness, accuracy, and availability of technology processing.

Establishes Appropriate Security Management Process Controls Activities

The management team should select and develop control activities that are designed and implemented to restrict technology access rights to authorised users in line with their job responsibilities and to protect your organisation’s assets from external threats.

Establishes Relevant Technology Acquisition, Development, and Maintenance Process Control Activities

Management should select and develop control activities pertaining to the acquisition, development, and maintenance of technology and its infrastructure to achieve the management team’s objectives.

SOC 2 CC5.2 requires that your organisation deploys control activities through policies that establish what is expected and in procedures that put policies into action.

CC5.3

CC5.3 highlights the following points of focus:

Creates Policies and Procedures to Support Implementation of Management’s Directives

Management should establish control activities that are built into business procedures as well as employees’ day-to-day activities through policies establishing what is expected and relevant procedures specifying actions.

Establishes Responsibility and Accountability for Executing Policies and Procedures

The management team should establish responsibility and accountability for control activities with management (or other appointed employees) of the business unit or function in which the related risks reside.

Performs in a Timely Manner

Responsible personnel should undertake control activities in a timely manner, as defined by the organisation’s policies and procedures.

Takes Remedial Action

Responsible personnel should investigate and act on matters identified because of undertaking control activities.

Performs Using Skilled Personnel

Competent personnel with sufficient authority should perform control activities conscientiously and with ongoing focus.

Reexamines Policies and Procedures

The management team should regularly review control activities to determine their continued relevance and refresh them when needed.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status.Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Staying Compliant
Computer Software
IT and Services
Growth