Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC1.1Commitment to integrity and ethical valuesSOC 2Control Environment

Official Requirement

The entity demonstrates a commitment to integrity and ethical values.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

The organization sets the tone from the top that security and ethics are non-negotiable. This shows up in a Code of Conduct that staff actually sign, policies that spell out consequences for violations, and leadership behavior that reinforces rather than undermines the rules. Auditors will look for whether the policies exist AND whether violations were ever acted upon.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Code of Conduct with annual acknowledgement

Implementation steps

  1. Distribute the Code of Conduct via email or the intranet and collect signed paper or digital acknowledgements, store in personnel files or a shared drive
  2. Set a calendar reminder to run the annual acknowledgement cycle; track completions in a spreadsheet and upload to your GRC platform as evidence
  3. Document any policy violations during the audit period and the disciplinary action taken, auditors want to see that consequences are real
  4. Ensure the Code of Conduct references the Information Security Policy so the two documents are explicitly connected

Tools / systems

Evidence artifacts

Evidence frequency: Annual; acknowledgement log exported at each audit window close

Documented disciplinary process for security policy violations

Implementation steps

  1. Reference disciplinary consequences in at least one policy document that all staff have acknowledged, the Code of Conduct is the most common vehicle
  2. When a security violation occurs, open a formal incident or HR ticket documenting the event and resolution, this creates an audit trail
  3. Confirm that the disciplinary policy applies equally to all levels including management; auditors are sensitive to policies that only apply downward

Tools / systems

Evidence artifacts

Evidence frequency: Per-event documentation; annual policy review sign-off