← SOC 2 Trust Services Criteria in plain English

CC5.1 CC5

Control Activities / CC5.1

Choosing controls that actually address the assessed risk

Think of it likeBuying the lock that fits the door you were worried about.

In plain English

Control activities are selected and developed to bring identified risks down to an acceptable level. The link runs from the risk assessment to the control, not the other way around.

Related CSF, CIS and ISO controls (unofficial mapping)