CC2 Security Required

Communication & Information

Complete guide to CC2 Communication & Information controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

3 Controls
0 Critical
0 High
CC2.1 medium

Information to Support Internal Control

You have an Information Security Policy (ISP) that is documented, current, and distributed to all employees. Security decisions are based on relevant data.

View official AICPA language

The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

What auditors look for

Information Security Policy document (dated within last 12 months), distribution list or acknowledgement records

CC2.2 low

Internal Communication of Control Information

Security policies, responsibilities, and objectives are actively communicated to all relevant employees — not just posted in a wiki nobody reads.

View official AICPA language

The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.

What auditors look for

Security policy communication emails/Slack announcements, all-hands security training records, policy wiki page view analytics

CC2.3 medium

External Communication

You communicate your security commitments to customers and third parties — through your Trust Portal, DPA, or vendor agreements. You also have a process for receiving security reports from external parties.

View official AICPA language

The entity communicates with external parties regarding matters affecting the functioning of internal control.

What auditors look for

Privacy policy, data processing agreements (DPAs), security page on website, vulnerability disclosure policy

Track all 3 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today