Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC2.1Obtains or generates and uses relevant quality informationSOC 2Communication and Information

Official Requirement

COSO Principle 13: The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Your security program runs on data: vulnerability scan results, access review outputs, incident logs, control monitoring dashboards. This criterion asks whether you are actually consuming that data to make decisions, not just collecting it. A GRC platform with 30 red controls that no one reviews does not satisfy CC2.1, the information must feed into how controls are managed.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

GRC platform or control monitoring dashboard with active review

Implementation steps

  1. Use your SIEM/monitoring platform as your primary data aggregation layer: vulnerability scan results, CIS benchmark scores, and SIEM alerts all feed into the same console
  2. Export and review control status on a defined cadence (monthly minimum), document the review date and any findings addressed
  3. Maintain a simple control status spreadsheet or your GRC platform evidence uploads that show which controls are passing and which are failing at any point in time
  4. Ensure that information from audits, penetration tests, and vulnerability scans is reviewed by the person accountable for the relevant control domain

Tools / systems

Evidence artifacts

Evidence frequency: Monthly review; evidence uploaded at each audit window