Communication & Information
Complete guide to CC2 Communication & Information controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
Information to Support Internal Control
Plain English
You have an Information Security Policy (ISP) that is documented, current, and distributed to all employees. Security decisions are based on relevant data.
View official AICPA language
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
What auditors look for
Information Security Policy document (dated within last 12 months), distribution list or acknowledgement records
Internal Communication of Control Information
Plain English
Security policies, responsibilities, and objectives are actively communicated to all relevant employees — not just posted in a wiki nobody reads.
View official AICPA language
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
What auditors look for
Security policy communication emails/Slack announcements, all-hands security training records, policy wiki page view analytics
External Communication
Plain English
You communicate your security commitments to customers and third parties — through your Trust Portal, DPA, or vendor agreements. You also have a process for receiving security reports from external parties.
View official AICPA language
The entity communicates with external parties regarding matters affecting the functioning of internal control.
What auditors look for
Privacy policy, data processing agreements (DPAs), security page on website, vulnerability disclosure policy
Track all 3 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today