Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
33 controls
CC1.1
Commitment to integrity and ethical values
Control Environment
6 evidence2 controls
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2Internal communication of information to support internal controlSOC 2Communication and Information
Official Requirement
COSO Principle 14: The entity internally communicates information, including objectives and responsibilities for internal control, to support the functioning of internal control.
Your staff know what the security program requires of them. Policies are published and accessible, security responsibilities are communicated through job descriptions and training, and the security team communicates changes to the environment that affect controls. The failure mode here is a program that exists on paper but is invisible to the people who need to operate it.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Published security policies accessible to all staff
Implementation Steps
Publish all security policies in a centralized location accessible to all staff (Confluence, Notion, Google Drive, or your GRC platform's policy portal)
Use your GRC platform to distribute policy updates and collect acknowledgements, this creates an audit trail showing staff were notified and accepted updated policies
When policies change materially, send a communication to affected staff explaining what changed and why, do not rely solely on a policy portal that staff rarely check
Maintain a policy inventory listing each policy, its owner, effective date, and next review date, this is also evidence for CC5.3
Typical Control Security incident and risk communication to relevant stakeholders
Implementation Steps
Define in the Incident Response Policy who receives communication at each incident severity level, Level 1 (critical) escalates to executive leadership; Level 2 goes to the security team and affected system owners
Document communication SLAs: internal notification within X hours of confirmed incident detection; external if contractually required
For risk register updates (CC3.2), ensure identified risks are communicated to the people who can remediate them, a risk register that only the security team reads is not effective internal communication
Use Jira or a ticketing system to route security findings and remediation tasks to the correct owner; the ticket assignment is the communication
Tools / Systems
Incident Response PolicyJira / Linear (security ticket routing)Slack (incident alerting)PagerDuty (escalation management)GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Typical Control Published security policies accessible to all staff
Evidence Artifacts
Policy inventory showing all active policies with effective dates and owners
GRC platform screenshot confirming policies are published and accessible
Sample policy update communication or acknowledgement record from the audit period
📅Policies reviewed annually; update communications per material policy change
Typical Control Security incident and risk communication to relevant stakeholders
Evidence Artifacts
Incident Response Policy showing internal notification requirements and escalation paths
Sample incident ticket showing internal communication was sent within the defined SLA
Remediation tickets for vulnerability or penetration test findings showing assignment to system owners
📅Per-incident documentation; quarterly risk communication meeting minutes
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Published security policies accessible to all staff
Implementation steps
Host all current policies on the company intranet or a shared drive; every employee must be able to access them without asking
Send an all-staff email when policies are updated; retain the email as evidence of communication
Use the annual training cycle to reinforce key policy requirements, training is also an internal communication mechanism
Maintain a policy inventory spreadsheet showing policy name, owner, version, and last review date
Tools / systems
Intranet / shared drive (policy hosting)
Email (policy update communications)
Spreadsheet (policy inventory)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Policy inventory spreadsheet with policy list, versions, and review dates
Screenshot or link confirming policies are published on the intranet or shared drive
Email communications sent when policies were updated during the audit period