Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC2.2Internal communication of information to support internal controlSOC 2Communication and Information

Official Requirement

COSO Principle 14: The entity internally communicates information, including objectives and responsibilities for internal control, to support the functioning of internal control.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Your staff know what the security program requires of them. Policies are published and accessible, security responsibilities are communicated through job descriptions and training, and the security team communicates changes to the environment that affect controls. The failure mode here is a program that exists on paper but is invisible to the people who need to operate it.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Published security policies accessible to all staff

Implementation steps

  1. Host all current policies on the company intranet or a shared drive; every employee must be able to access them without asking
  2. Send an all-staff email when policies are updated; retain the email as evidence of communication
  3. Use the annual training cycle to reinforce key policy requirements, training is also an internal communication mechanism
  4. Maintain a policy inventory spreadsheet showing policy name, owner, version, and last review date

Tools / systems

Evidence artifacts

Evidence frequency: Annual policy review; per-change communications

Security incident and risk communication to relevant stakeholders

Implementation steps

  1. Document the internal escalation path for security incidents in the Incident Response Plan
  2. When a vulnerability scan or penetration test produces findings, assign remediation tickets to the correct system owners and track them to closure
  3. Hold quarterly security updates with management to communicate risk posture changes, significant incidents, and control gaps

Tools / systems

Evidence artifacts

Evidence frequency: Per-incident; quarterly management communication