SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC5.2: CC5.2 General controls over technology (COSO principle 11)

General controls over technology are selected and developed to support objectives. Points of focus: management understands how business processes and automated controls depend on technology general controls; controls over infrastructure support complete, accurate and available processing; security management controls limit access rights to authorised users in line with their jobs and protect assets from external threats; and controls over acquisition, development and maintenance of technology support management's objectives.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 291 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 61 controls

  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.6.2 10.6.2 Systems configured to correct and consistent time
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 11.2.2 11.2.2 Inventory of authorized wireless access points
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.2 11.5.2 Change detection on critical files
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.2.3 2.2.3 Primary functions with different security levels managed
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.4.2 6.4.2 Automated web attack detection and prevention
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 9.5.1 9.5.1 Protection of POI devices from tampering
  • 9.5.1.1 9.5.1.1 Current register of POI devices
  • 3.7.1 3.7.1 Generation of strong cryptographic keys
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.4.3 6.4.3 Payment page script management
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.3 6.5.3 Separate pre-production from production
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • 8.6.3 8.6.3 System account passwords protected against misuse

CIS Controls v8 · 44 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.10 Apply Secure Design Principles in Application Architectures
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-18.4 Validate Security Measures
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.4 Implement and Manage a Firewall on Servers
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-8.3 Ensure Adequate Audit Log Storage
  • CIS-8.4 Standardize Time Synchronization
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

NIST SP 800-53 Rev 5 · 33 controls

FedRAMP High · 24 controls

  • AC-19 Access Control for Mobile Devices
  • AU-2 Event Logging
  • CM-6 Configuration Settings
  • CM-8(3) Automated Unauthorized Component Detection
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-2(12) Acceptance of PIV Credentials
  • IA-5(1) Password-Based Authentication
  • MA-4 Nonlocal Maintenance
  • PL-8 Security and Privacy Architectures
  • SA-8 Security and Privacy Engineering Principles
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SC-10 Network Disconnect
  • SC-12 Cryptographic Key Establishment and Management
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-28(1) Cryptographic Protection
  • SC-39 Process Isolation
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SC-7(4) External Telecommunications Services
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

FedRAMP Moderate · 24 controls

  • AC-19 Access Control for Mobile Devices
  • AU-2 Event Logging
  • CM-6 Configuration Settings
  • CM-8(3) Automated Unauthorized Component Detection
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-2(12) Acceptance of PIV Credentials
  • IA-5(1) Password-Based Authentication
  • MA-4 Nonlocal Maintenance
  • PL-8 Security and Privacy Architectures
  • SA-8 Security and Privacy Engineering Principles
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SC-10 Network Disconnect
  • SC-12 Cryptographic Key Establishment and Management
  • SC-15 Collaborative Computing Devices and Applications
  • SC-18 Mobile Code
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-28(1) Cryptographic Protection
  • SC-39 Process Isolation
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SC-7(4) External Telecommunications Services
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

ISO 27001:2022 · 14 controls

  • 5.23 Information security for use of cloud services
  • 8.15 Logging
  • 8.18 Use of privileged utility programs
  • 8.2 Privileged access rights
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.32 Change management
  • 8.4 Access to source code
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

CMMC 2.0 · 13 controls

HIPAA Security Rule · 12 controls

ISO 27002:2022 · 11 controls

  • 5.23 Information security for use of cloud services
  • 8.18 Use of privileged utility programs
  • 8.21 Security of network services
  • 8.24 Use of cryptography
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

NIST SP 800-66 Rev 2 · 10 controls

ISO 27701:2019 · 7 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.11.2 Security in development and support processes
  • 6.14.2 Redundancies
  • 6.7.1 Cryptographic controls
  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management

ISO/IEC 42001:2023 · 5 controls

  • A.4 Resources for AI systems
  • A.6 AI system life cycle
  • A.6.2.6 AI system operation and monitoring
  • A.6.2.8 AI system recording of event logs
  • A.7 Data for AI systems
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-171 Rev 3 · 3 controls

  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies
  • SEC01-BP06 Automate deployment of standard security controls
  • SEC03-BP05 Define permission guardrails for your organization
  • ASBv3-PV-1 Define and establish secure configurations
  • PV-2 Audit and enforce secure configurations

C5 (Germany) · 2 controls

  • C5-DEV-03 Policies for changes to information systems
  • C5-IDM-01 Policy for user accounts and access rights
  • CFTC-SS-4 Systems Operations Category
  • CFTC-SS-5 Systems Development and Quality Assurance Category

NIST SP 800-218 · 2 controls

  • E8-UAH-ML2 User Application Hardening - Maturity Level 2
  • CPS230-P25 Information and Technology Capability and Asset Health

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • ASD37-11 Operating system hardening (Very Good)
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability

DORA · 1 control

EU AI Act · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

NIST SP 800-172 · 1 control

  • 3.4.3e Automated Inventory of System Components

UK Cyber Essentials · 1 control

  • CE-SC.1 Remove or Disable Unused Software

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 291 it maps to, and the evidence behind each claim, over MCP and REST.