CC5.3 CC5 · Control Activities · Security (Common Criteria)

CC5.3 — Policies and procedures

COSO Principle 12 — The entity deploys control activities through policies that establish what is expected and procedures that put policies into action.

Also written as CC 5.3, TSC CC5.3, SOC2 CC5.3, SOC 2 Type 2 CC5.3.

What SOC 2 CC5.3 requires

Policies and procedures is one of 3 criteria in the Control Activities (CC5) series of the Security (Common Criteria) category. COSO Principle 12 — The entity deploys control activities through policies that establish what is expected and procedures that put policies into action. CC5 links the risks from CC3 to concrete control activities, so the strongest evidence is a control matrix showing which control addresses which risk and who owns it.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC5.3, gather artefacts such as:

  • Approved policy set with version history
  • Procedure documents for key control activities
  • Annual policy review and re-approval records
  • Staff acknowledgement of policies

ISO 27001 mapping

CC5.3 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.1, A.5.37. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC5.3 rather than duplicating work.

Map CC5.3 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC5.3 in the Risk Register.

Other Control Activities criteria

CC5.1 Control activities mitigating risk CC5.2 General controls over technology

All CC5 Control Activities criteria →

Frequently asked questions

Is CC5.3 required for a SOC 2 report?

Yes. CC5.3 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC5.3?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC5.3 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC5.3 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.

Does SOC 2 CC5.3 map to ISO 27001?

Yes — CC5.3 aligns with ISO 27001:2022 Annex A control(s) A.5.1, A.5.37. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.