SOC 2 SOC2-CC5.1: CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
Control activities are chosen and developed to bring risks to objectives down to acceptable levels. Points of focus: control activities carry out the risk responses from the risk assessment; the environment, complexity and scope of operations shape the choice; the business processes that need controls are determined; a mix of manual and automated, preventive and detective controls is used; controls are applied at appropriate levels; and incompatible duties are segregated, or alternative controls are designed where segregation is impractical.
This control maps to 163 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-CC5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.