Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC5.2Selects and develops general controls over technologySOC 2Control Activities

Official Requirement

COSO Principle 11: The entity also selects and develops general control activities over technology to support the achievement of objectives.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

The technology infrastructure supporting your security program is itself controlled. This means your monitoring tools are reliable, your logging infrastructure is complete, your GRC platform has not been tampered with, and the technology you rely on to enforce controls has its own security controls. It is not enough to say you have a SIEM if anyone can delete SIEM logs without detection.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Log integrity and SIEM infrastructure controls

Implementation steps

  1. Configure your SIEM/monitoring platform to forward all logs to a remote log server or your IDS/network monitoring platform node that production server administrators cannot directly access, this prevents log tampering by insiders with server access
  2. Enable your SIEM/monitoring platform file integrity monitoring (FIM) on critical log directories to detect if log files are modified or deleted
  3. Restrict access to the your SIEM/monitoring platform manager and your IDS/network monitoring platform consoles to the security team only, separate credentials from production system administration
  4. Alert when logging gaps occur: if a vulnerability/configuration management agents goes silent or your IDS/network monitoring platform stops receiving traffic from a segment, that is a monitoring failure requiring investigation

Tools / systems

Evidence artifacts

Evidence frequency: Configuration reviewed at each audit window; FIM alerts active continuously

GRC platform access controls and configuration management

Implementation steps

  1. Limit your GRC platform or your GRC tool admin access to the security team; read-only access is appropriate for most staff
  2. Apply the same access control standards to GRC tooling as to production systems: MFA required, access reviewed quarterly, offboarding includes GRC access revocation
  3. Maintain the configuration of your GRC integrations (cloud connectors, SIEM integrations) as documented and reviewed, connector failures mean monitoring gaps

Tools / systems

Evidence artifacts

Evidence frequency: Quarterly access review; per-offboarding confirmation