SOC 2 SOC2-CC1.1: CC1.1 Commitment to integrity and ethical values (COSO principle 1)
The organisation shows through direction, decisions and behaviour that integrity and ethics matter to how it runs its controls. Points of focus: leadership sets the tone at the top; expected conduct is written into a code that staff, outsourced providers and partners understand; performance of individuals and teams is judged against that code; departures from it are found and corrected promptly and consistently; and contractors and vendor staff are brought within the same conduct expectations, adherence checks and corrective action.
This control maps to 54 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-CC1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.