SOC 2 CC5.2: General Controls Over Technology

Reviewed by Ali Aleali, CISSP, CCSP · Last reviewed July 29, 2026

SOC 2 CC5.2 requires an organization to select and develop general control activities over technology so its systems support the objectives the business depends on. It is the umbrella criterion for technology general controls, and most of the depth it points to lives in the CC6, CC7, and CC8 series that follow.

CC5.2 at a glance

What does SOC 2 CC5.2 require?

The entity also selects and develops general control activities over technology to support the achievement of objectives.

AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (TSC section 100), 2017, revised 2022. © AICPA. Quoted for purposes of commentary and reference.

CC5.2 sits directly after CC5.1, which requires an organization to select control activities from its risks. Where CC5.1 covers control activities in general, CC5.2 narrows to the subset that governs technology: the controls that keep infrastructure, access, and software behaving the way the business assumes they do.

The criterion maps to COSO Principle 11. Its role in the framework is to name technology general controls as a distinct category and require that they exist, without prescribing the detail of how each one operates. That detail is where the later Common Criteria series come in. CC5.2 is the doorway to CC6 (logical and physical access), CC7 (system operations, monitoring, and incident response), and CC8 (change management), and the bulk of the evidence an auditor examines for technology general controls is described under those criteria rather than here.

Because CC5.2 is a bridge, this reference is deliberately short. The sections below summarize the points of focus and the shape of the evidence, then point to the child criteria that carry the depth.

What are the CC5.2 points of focus?

The AICPA defines 4 points of focus for CC5.2. Because the Trust Services Criteria are AICPA copyrighted material, the points of focus below are paraphrased and grouped by theme rather than reproduced verbatim; consult the official TSC document for exact wording.

  • Technology dependency. The organization determines how business processes depend on technology and, in turn, on the general controls that keep that technology reliable.
  • Infrastructure controls. Relevant control activities are established over technology infrastructure, so the systems processes run on are configured and maintained to a known baseline. This is developed in the CC6 and CC7 series.
  • Security management controls. Access is restricted to authorized users and assets are protected from external threats. This is the subject of CC6.1 and the monitoring criteria in CC7.
  • Acquisition, development, and maintenance controls. Control activities govern how technology is acquired, built, and changed, which CC8.1 covers in full.

How do you meet CC5.2 in cloud environments?

Cloud environments meet CC5.2 by establishing technology general controls across the three areas the child criteria detail:

How do you meet CC5.2 on-prem?

On-prem environments establish the same categories of technology general control, applied to owned hardware and self-managed software:

  • Infrastructure baselines through hardened build standards and configuration management.
  • Access management through directory-based accounts, privileged-access controls, and periodic reviews, as detailed under CC6.1.
  • Vulnerability and monitoring controls through internal scanning and log review, as detailed under CC7.1 and CC7.2.
  • Change controls through a change-management process with review and approval, as detailed under CC8.1.

Cloud vs on-prem at a glance

Technology general control theme Cloud implementation On-prem implementation
Infrastructure Configuration as code with provider guardrails Hardened build standards and configuration management
Security management (access) Identity and least-privilege access (CC6.1) Directory accounts and privileged-access controls (CC6.1)
Acquisition and change Pipeline gates and release approvals (CC8.1) Change-management process with approval (CC8.1)

What evidence do auditors expect for CC5.2?

Artifact What it demonstrates Cadence
Baseline configuration records Infrastructure is maintained to a known state Point-in-time plus on change
Access control configurations and role separation Access is restricted to authorized users Continuous
SAST, DAST, and SCA scan results Acquisition and development controls operate Per build or release
Change and release approval records Technology changes are controlled Per change

A common gap: technology general controls that are assumed rather than evidenced

A common gap that comes up during readiness assessments is treating technology general controls as self-evident because the platform "handles it," when the evidence that ties infrastructure, access, and change controls back to CC5.2 lives across the CC6, CC7, and CC8 criteria and has to be produced there.

Watch out: SME review needed before publishing

Ali to supply a real, anonymized readiness-assessment example of how a company mistook a platform default for a technology general control, or otherwise had a CC5.2 gap that only showed up once the CC6/CC7/CC8 evidence was examined. No anecdote has been invented here.

How does CC5.2 map to ISO 27001:2022?

ISO 27001:2022 Annex A controls Overlap type SOC 2 evidence reusable
A 5.3 (Segregation of duties), Annex A 8 broadly (technological controls) Full Baseline configuration records, SAST/DAST/SCA scan results, access control configurations, role-separation evidence

The overlap is full because ISO 27001's Annex A 8 covers the same technology general controls that CC5.2 names, and A 5.3 addresses the segregation of duties that runs through them. The SOC 2 to ISO 27001 control mapping covers the full crosswalk across all five Trust Services Categories.

Build technology general controls that hold up in an audit

Truvo helps you tie access, monitoring, and change controls back to the criteria as part of an effective security program.

Related criteria

CC5.2 follows CC5.1, which requires selecting control activities from risk, and precedes CC5.3, which deploys control activities through policies and procedures. As the umbrella for technology general controls, CC5.2 points down to the criteria that carry the detail: logical access security (CC6.1), vulnerability management (CC7.1), security monitoring (CC7.2), and change management (CC8.1).

Part of Truvo's criterion-by-criterion SOC 2 reference series

Browse every criterion in the Framework Explorer or start from the Trust Services Criteria guide. For a second set of eyes on control design before an audit as part of an effective security program, Truvo runs scoping calls.

 

Frequently Asked Questions

What does SOC 2 CC5.2 mean?

SOC 2 CC5.2 requires an organization to select and develop general control activities over technology to support the achievement of its objectives. It maps to COSO Principle 11 and is the umbrella criterion for technology general controls, covering infrastructure, security management (access), and technology acquisition, development, and maintenance. The detailed controls it names are developed in the CC6, CC7, and CC8 series.

What evidence satisfies CC5.2?

Because CC5.2 is a bridge criterion, its evidence is the technology general control evidence produced under the later criteria: baseline configuration records, access control configurations and role-separation evidence, vulnerability and monitoring output, and change and release approval records. An auditor confirms these categories exist and traces them to the CC6, CC7, and CC8 criteria that describe each in full.

How is CC5.2 different from CC5.1?

CC5.1 requires an organization to select and develop control activities in general, chosen from its actual risks. CC5.2 narrows to the subset of those control activities that govern technology, naming infrastructure, security management, and acquisition and development as the three areas of technology general control. CC5.1 is the general case; CC5.2 is its technology-specific companion.

Which criteria carry the detail behind CC5.2?

CC5.2 points down to three later series. CC6 covers logical and physical access, starting with logical access security (CC6.1). CC7 covers system operations, including vulnerability management (CC7.1) and security monitoring (CC7.2). CC8 covers change management (CC8.1).

Ready to Start Your Compliance Journey?

Get a clear, actionable roadmap with our readiness assessment.

Share this article:

About the Author

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.

How Ready Are You for SOC 2?

Score your security program in under 5 minutes. Free.

Take the Scorecard
Framework Explorer BETA Browse SOC 2 controls, guidance, and evidence — free.