SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC5.1: CC5.1 Selecting control activities that mitigate risk (COSO principle 10)

Control activities are chosen and developed to bring risks to objectives down to acceptable levels. Points of focus: control activities carry out the risk responses from the risk assessment; the environment, complexity and scope of operations shape the choice; the business processes that need controls are determined; a mix of manual and automated, preventive and detective controls is used; controls are applied at appropriate levels; and incompatible duties are segregated, or alternative controls are designed where segregation is impractical.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 163 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 25 controls

  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.6.1 12.6.1 Formal security awareness program
  • 12.6.3.1 12.6.3.1 Awareness training covers phishing and social engineering
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.2 6.2.2 Annual secure software training for developers
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.5.1.2 9.5.1.2 Periodic inspection of POI device surfaces
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months

CIS Controls v8 · 15 controls

  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-15.3 Classify Service Providers
  • CIS-16.13 Conduct Application Penetration Testing
  • CIS-16.14 Conduct Threat Modeling
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-18.4 Validate Security Measures
  • CIS-3.7 Establish and Maintain a Data Classification Scheme
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.8 Define and Maintain Role-Based Access Control
  • CIS-7.2 Establish and Maintain a Remediation Process

NIST SP 800-53 Rev 5 · 15 controls

ISO 27001:2022 · 11 controls

  • 5.15 Access control
  • 5.7 Threat intelligence
  • 5.8 Information security in project management
  • 8.2 Privileged access rights
  • 8.24 Use of cryptography
  • 8.26 Application security requirements
  • 8.28 Secure coding
  • 8.3 Information access restriction
  • 8.30 Outsourced development
  • 8.7 Protection against malware
  • 8.9 Configuration management

FedRAMP Moderate · 10 controls

  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(7) Review of User Privileges
  • CP-9(1) Testing for Reliability and Integrity
  • PL-10 Baseline Selection. Select a control baseline for the system
  • PL-11 Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions
  • PL-8 Security and Privacy Architectures
  • RA-9 Criticality Analysis (RA-9)
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • RA-7 Risk Response

FedRAMP High · 9 controls

  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(7) Review of User Privileges
  • CP-9(1) Testing for Reliability and Integrity
  • PL-10 Baseline Selection. Select a control baseline for the system
  • PL-11 Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions
  • PL-8 Security and Privacy Architectures
  • RA-9 Criticality Analysis (RA-9)
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))

HIPAA Security Rule · 9 controls

  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration

ISO 27002:2022 · 7 controls

  • 5.1 Policies for information security
  • 5.27 Learning from information security incidents
  • 5.29 Information security during disruption
  • 5.3 Segregation of duties
  • 5.8 Information security in project management
  • 8.18 Use of privileged utility programs
  • 8.29 Security testing in development and acceptance

NIST SP 800-66 Rev 2 · 7 controls

ISO 22301:2019 · 6 controls

  • 6.1 Actions to address risks and opportunities
  • 8.1 Operational planning and control
  • 8.3 Business continuity strategies and solutions
  • 8.3.2 Identification of strategies and solutions
  • 8.3.3 Selection of strategies and solutions
  • 8.3.5 Implementation of solutions

CMMC 2.0 · 5 controls

ISO 27701:2019 · 5 controls

  • 5.4.1 Actions to address risks and opportunities
  • 5.6.1 Operational planning and control
  • 5.6.3 Information security risk treatment
  • 6.14 Information security aspects of business continuity management
  • 8.4 Privacy by design and privacy by default

ISO/IEC 42001:2023 · 5 controls

  • 6.1.2 AI risk assessment
  • 6.1.3 AI risk treatment
  • 8.1 Operational planning and control
  • 8.3 AI risk treatment
  • A.9 Use of AI systems
  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

NIS2 Directive · 3 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-171 Rev 3 · 3 controls

  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-24 Design and Embedding of Internal Controls

C5 (Germany) · 2 controls

  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

EU AI Act · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-MONITORING Monitoring Controls

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability

DORA · 1 control

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 163 it maps to, and the evidence behind each claim, over MCP and REST.