Frameworks / SOC 2 / SOC2-CC5.2 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC5.2: CC5.2 General controls over technology (COSO principle 11) General controls over technology are selected and developed to support objectives. Points of focus: management understands how business processes and automated controls depend on technology general controls; controls over infrastructure support complete, accurate and available processing; security management controls limit access rights to authorised users in line with their jobs and protect assets from external threats; and controls over acquisition, development and maintenance of technology support management's objectives.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 291 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.5 1.2.5 Allowed services, protocols and ports justified 1.5.1 1.5.1 Security controls on dual-connected devices 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.1.2 10.2.1.2 Logs capture all administrative actions 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.3.2 10.3.2 Audit log files protected from modification 10.6.2 10.6.2 Systems configured to correct and consistent time 10.6.3 10.6.3 Time sync configuration and time data protected 11.2.2 11.2.2 Inventory of authorized wireless access points 11.3.1.3 11.3.1.3 Internal scans after significant change 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.2 11.5.2 Change detection on critical files 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.3.4 12.3.4 Annual review of hardware and software technologies 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 12.6.1 12.6.1 Formal security awareness program 2.2.1 2.2.1 System configuration standards maintained 2.2.2 2.2.2 Vendor default accounts managed 2.2.3 2.2.3 Primary functions with different security levels managed 2.2.4 2.2.4 Only necessary functionality enabled 2.2.5 2.2.5 Insecure services, protocols or daemons secured 2.2.6 2.2.6 System security parameters configured against misuse 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure 2.3.2 2.3.2 Wireless encryption keys changed on triggers 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations 3.7.7 3.7.7 Prevent unauthorized substitution of keys 3.7.9 3.7.9 Key guidance for service provider customers 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates 5.4.1 5.4.1 Mechanisms detect and protect against phishing 6.2.1 6.2.1 Secure development of bespoke and custom software 6.2.4 6.2.4 Engineering techniques against common software attacks 6.4.1 6.4.1 Public web application review or automated protection 6.4.2 6.4.2 Automated web attack detection and prevention 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 8.3.7 8.3.7 No reuse of last four passwords 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.4.3 8.4.3 MFA for remote access that could reach CDE 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.3 9.2.3 Physical protection of network hardware and lines 9.2.4 9.2.4 Locking of consoles in sensitive areas 9.4.1 9.4.1 Physical security of all media 9.4.4 9.4.4 Management approval for media leaving facility 9.5.1 9.5.1 Protection of POI devices from tampering 9.5.1.1 9.5.1.1 Current register of POI devices 3.7.1 3.7.1 Generation of strong cryptographic keys 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 6.4.3 6.4.3 Payment page script management 6.5.1 6.5.1 Change control procedure for production 6.5.3 6.5.3 Separate pre-production from production 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts 8.6.3 8.6.3 System account passwords protected against misuse CIS-1.2 Address Unauthorized Assets CIS-1.3 Utilize an Active Discovery Tool CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory CIS-10.5 Enable Anti-Exploitation Features CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.3 Securely Manage Network Infrastructure CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-13.5 Manage Access Control for Remote Assets CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-16.1 Establish and Maintain a Secure Application Development Process CIS-16.10 Apply Secure Design Principles in Application Architectures CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure CIS-18.4 Validate Security Measures CIS-2.1 Establish and Maintain a Software Inventory CIS-2.2 Ensure Authorized Software is Currently Supported CIS-2.3 Address Unauthorized Software CIS-2.4 Utilize Automated Software Inventory Tools CIS-3.13 Deploy a Data Loss Prevention Solution CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure CIS-4.4 Implement and Manage a Firewall on Servers CIS-4.6 Securely Manage Enterprise Assets and Software CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets CIS-5.3 Disable Dormant Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-6.3 Require MFA for Externally-Exposed Applications CIS-6.5 Require MFA for Administrative Access CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-8.3 Ensure Adequate Audit Log Storage CIS-8.4 Standardize Time Synchronization CIS-8.5 Collect Detailed Audit Logs CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions AC-19 Access Control for Mobile Devices AU-2 Event Logging CM-6 Configuration Settings CM-8(3) Automated Unauthorized Component Detection CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-2(12) Acceptance of PIV Credentials IA-5(1) Password-Based Authentication MA-4 Nonlocal Maintenance PL-8 Security and Privacy Architectures SA-8 Security and Privacy Engineering Principles SA-9(2) Identification of Functions, Ports, Protocols, and Services SC-10 Network Disconnect SC-12 Cryptographic Key Establishment and Management SC-15 Collaborative Computing Devices and Applications SC-18 Mobile Code SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-28(1) Cryptographic Protection SC-39 Process Isolation SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2)) AC-19 Access Control for Mobile Devices AU-2 Event Logging CM-6 Configuration Settings CM-8(3) Automated Unauthorized Component Detection CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-2(12) Acceptance of PIV Credentials IA-5(1) Password-Based Authentication MA-4 Nonlocal Maintenance PL-8 Security and Privacy Architectures SA-8 Security and Privacy Engineering Principles SA-9(2) Identification of Functions, Ports, Protocols, and Services SC-10 Network Disconnect SC-12 Cryptographic Key Establishment and Management SC-15 Collaborative Computing Devices and Applications SC-18 Mobile Code SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-28(1) Cryptographic Protection SC-39 Process Isolation SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2)) 5.23 Information security for use of cloud services 8.15 Logging 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.20 Networks security 8.21 Security of network services 8.25 Secure development life cycle 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.28 Secure coding 8.32 Change management 8.4 Access to source code 8.8 Management of technical vulnerabilities 8.9 Configuration management 5.23 Information security for use of cloud services 8.18 Use of privileged utility programs 8.21 Security of network services 8.24 Use of cryptography 8.25 Secure development life cycle 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.28 Secure coding 8.32 Change management 8.8 Management of technical vulnerabilities 8.9 Configuration management 6.11 Systems acquisition, development and maintenance 6.11.1 Security requirements of information systems 6.11.2 Security in development and support processes 6.14.2 Redundancies 6.7.1 Cryptographic controls 6.9.5 Control of operational software 6.9.6 Technical vulnerability management A.4 Resources for AI systems A.6 AI system life cycle A.6.2.6 AI system operation and monitoring A.6.2.8 AI system recording of event logs A.7 Data for AI systems NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-PR.PS-01 Configuration management practices are established and applied NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies SEC01-BP06 Automate deployment of standard security controls SEC03-BP05 Define permission guardrails for your organization ASBv3-PV-1 Define and establish secure configurations PV-2 Audit and enforce secure configurations C5-DEV-03 Policies for changes to information systems C5-IDM-01 Policy for user accounts and access rights CFTC-SS-4 Systems Operations Category CFTC-SS-5 Systems Development and Quality Assurance Category E8-UAH-ML2 User Application Hardening - Maturity Level 2 CPS230-P25 Information and Technology Capability and Asset Health CPS234-21 Implementation of Information Security Controls ASD37-11 Operating system hardening (Very Good) AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure 3.4.3e Automated Inventory of System Components CE-SC.1 Remove or Disable Unused Software Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 291 it maps to, and the evidence behind each claim, over MCP and REST.