{
  "node_id": "soc2-cc5-control-activities",
  "title": "AICPA SOC 2 Common Criteria CC5 - Control Activities (COSO Principles 10-12)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "CC5 is the Control Activities series of the SOC 2 Common Criteria (COSO Principles 10-12). It requires the entity to select and develop control activities that contribute to the mitigation of risks to acceptable levels, to select and develop general control activities over technology, and to deploy control activities through policies that establish what is expected and procedures that put policies into action. The criteria are CC5.1-CC5.3.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 5
}