CC5 Security Required

Control Activities

Complete guide to CC5 Control Activities controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

3 Controls
0 Critical
2 High
CC5.1 high

Controls Over Technology

You have selected appropriate technical controls (encryption, MFA, logging, etc.) that address the risks identified in your risk assessment. Controls are commensurate with the risk level.

View official AICPA language

The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

What auditors look for

Control matrix showing risk-to-control mapping, technical control configuration screenshots (MFA enabled, encryption settings)

CC5.2 high

Controls Over Technology Infrastructure

Your technology infrastructure has controls in place: secure configuration baselines, patching policies, and hardening standards for servers, containers, and cloud environments.

View official AICPA language

The entity also selects and develops general control activities over technology to support the achievement of objectives.

What auditors look for

CIS Benchmark compliance reports, cloud security posture reports (AWS Security Hub, GCP SCC), patch management records

CC5.3 medium

Policy Deployment

Security policies are deployed as executable procedures — not just documents. Employees know what to do, not just what the policy says.

View official AICPA language

The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.

What auditors look for

Procedure documents (runbooks, SOPs), training records showing employees were trained on procedures, evidence procedures are followed

Track all 3 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today