Skip to content

Latest commit

 

History

History
21 lines (21 loc) · 2.37 KB

cc52.md

File metadata and controls

21 lines (21 loc) · 2.37 KB

SOC2 - CC5.2

COSO Principle 11: The entity also selects and develops general control activities over technology to support the achievement of objectives

Determines Dependency Between the Use of Technology in Business Processes and Technology General Controls

Management understands and determines the dependency and linkage between business processes, automated control activities, and technology general controls

Establishes Relevant Technology Infrastructure Control Activities

Management selects and develops control activities over the technology infrastructure, which are designed and implemented to help ensure the completeness, accuracy, and availability of technology processing

Establishes Relevant Security Management Process Controls Activities

Management selects and develops control activities that are designed and implemented to restrict technology access rights to authorized users commensurate with their job responsibilities and to protect the entity’s assets from external threats

Establishes Relevant Technology Acquisition, Development, and Maintenance Process Control Activities

Management selects and develops control activities over the acquisition, development, and maintenance of technology and its infrastructure to achieve management’s objectives.

Mapped SCF controls