Control Activities
Complete guide to CC5 Control Activities controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
Controls Over Technology
Plain English
You have selected appropriate technical controls (encryption, MFA, logging, etc.) that address the risks identified in your risk assessment. Controls are commensurate with the risk level.
View official AICPA language
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
What auditors look for
Control matrix showing risk-to-control mapping, technical control configuration screenshots (MFA enabled, encryption settings)
Controls Over Technology Infrastructure
Plain English
Your technology infrastructure has controls in place: secure configuration baselines, patching policies, and hardening standards for servers, containers, and cloud environments.
View official AICPA language
The entity also selects and develops general control activities over technology to support the achievement of objectives.
What auditors look for
CIS Benchmark compliance reports, cloud security posture reports (AWS Security Hub, GCP SCC), patch management records
Policy Deployment
Plain English
Security policies are deployed as executable procedures — not just documents. Employees know what to do, not just what the policy says.
View official AICPA language
The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.
What auditors look for
Procedure documents (runbooks, SOPs), training records showing employees were trained on procedures, evidence procedures are followed
Track all 3 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today