Skip to main content

๐Ÿ’ผ CC2 Communication and Information

  • Contextual name: ๐Ÿ’ผ CC2 Communication and Information
  • ID: /frameworks/soc-2/cc2
  • Located in: ๐Ÿ’ผ SOC 2

Descriptionโ€‹

Empty...

Similarโ€‹

  • Internal
    • ID: dec-b-ab1127b9

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ CC2.1 The entity obtains or generates and uses relevant, quality information to\ \ support the functioning of internal control.4
ย ย ย ย ๐Ÿ’ผ CC2.1-1 Identifies Information Requirements
ย ย ย ย ๐Ÿ’ผ CC2.1-2 Captures Internal and External Sources of Data
ย ย ย ย ๐Ÿ’ผ CC2.1-3 Processes Relevant Data Into Information
ย ย ย ย ๐Ÿ’ผ CC2.1-4 Maintains Quality Throughout Processing
๐Ÿ’ผ CC2.2 The entity internally communicates information, including objectives and\ \ responsibilities for internal control, necessary to support the functioning\ \ of internal control.13
ย ย ย ย ๐Ÿ’ผ CC2.2-1 Communicates Internal Control Information
ย ย ย ย ๐Ÿ’ผ CC2.2-2 Communicates With the Board of Directors
ย ย ย ย ๐Ÿ’ผ CC2.2-3 Provides Separate Communication Lines
ย ย ย ย ๐Ÿ’ผ CC2.2-4 Selects Relevant Method of Communication
ย ย ย ย ๐Ÿ’ผ CC2.2-5 Communicates Responsibilities
ย ย ย ย ๐Ÿ’ผ CC2.2-6 Communicates Information on Reporting Failures, Incidents, Concerns, and Other Matters
ย ย ย ย ๐Ÿ’ผ CC2.2-7 Communicates Objectives and Changes to Objectives
ย ย ย ย ๐Ÿ’ผ CC2.2-8 Communicates Information to Improve Security Knowledge and Awareness
ย ย ย ย ๐Ÿ’ผ CC2.2-9 Communicates Information to Improve Privacy Knowledge and Awareness
ย ย ย ย ๐Ÿ’ผ CC2.2-10 Communicates Incident Reporting Methods
ย ย ย ย ๐Ÿ’ผ CC2.2-11 Communicates Information About System Operation and Boundaries
ย ย ย ย ๐Ÿ’ผ CC2.2-12 Communicates System Objectives
ย ย ย ย ๐Ÿ’ผ CC2.2-13 Communicates System Changes
๐Ÿ’ผ CC2.3 The entity communicates with external parties regarding matters affecting\ \ the functioning of internal control.12
ย ย ย ย ๐Ÿ’ผ CC2.3-1 Communicates to External Parties
ย ย ย ย ๐Ÿ’ผ CC2.3-2 Enables Inbound Communications
ย ย ย ย ๐Ÿ’ผ CC2.3-3 Communicates With the Board of Directors
ย ย ย ย ๐Ÿ’ผ CC2.3-4 Provides Separate Communication Lines
ย ย ย ย ๐Ÿ’ผ CC2.3-5 Selects Relevant Method of Communication
ย ย ย ย ๐Ÿ’ผ CC2.3-6 Communicates Objectives Related to Confidentiality and Changes to Those Objectives
ย ย ย ย ๐Ÿ’ผ CC2.3-7 Communicates Objectives Related to Privacy and Changes to Those Objectives
ย ย ย ย ๐Ÿ’ผ CC2.3-8 Communicates Incident Reporting Methods
ย ย ย ย ๐Ÿ’ผ CC2.3-9 Communicates Information About System Operation and Boundaries
ย ย ย ย ๐Ÿ’ผ CC2.3-10 Communicates System Objectives
ย ย ย ย ๐Ÿ’ผ CC2.3-11 Communicates System Responsibilities
ย ย ย ย ๐Ÿ’ผ CC2.3-12 Communicates Information on Reporting System Failures, Incidents, Concerns, and Other Matters