SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC2.2: CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)

Information needed for internal control, including objectives and control duties, is communicated inside the organisation. Points of focus: a process lets all personnel understand and carry out their control duties; management and the board exchange what each needs; separate channels such as a whistle-blowing line exist when normal routes fail; the method suits timing, audience and content; people who design, run or monitor controls are told their responsibilities and changes to them; staff know how to report failures, incidents and concerns; objectives and changes are communicated promptly; a security awareness programme builds knowledge and good behaviour; and at system level, staff are told how the system and its boundaries operate, its objectives, and changes that affect them. The 2022 revision adds, for privacy engagements, a privacy awareness programme for personnel and telling staff how to report a suspected privacy incident.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 146 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 29 controls

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned
  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 11.1.2 11.1.2 Roles for security testing assigned and understood
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.6.3.1 12.6.3.1 Awareness training covers phishing and social engineering
  • 12.6.3.2 12.6.3.2 Awareness training covers acceptable use of end-user technologies
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 3.7.8 3.7.8 Key custodians formally acknowledge responsibilities
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 4.1.2 4.1.2 Requirement 4 roles and responsibilities assigned
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 5.1.2 5.1.2 Requirement 5 roles and responsibilities assigned
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 7.1.2 7.1.2 Requirement 7 roles and responsibilities assigned
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 9.1.2 9.1.2 Requirement 9 roles and responsibilities assigned
  • 9.5.1.3 9.5.1.3 Training for personnel in POI environments
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 3.1.2 3.1.2 Assigned duties for Requirement 3 activities
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained
  • 8.1.2 8.1.2 Requirement 8 roles and responsibilities assigned

CIS Controls v8 · 10 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.5 Assign Key Roles and Responsibilities
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

NIST SP 800-53 Rev 5 · 10 controls

FedRAMP High · 9 controls

  • AT-2 Literacy Training and Awareness
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • IR-8 Incident Response Plan
  • PL-2 System Security and Privacy Plans
  • PL-4 Rules of Behavior
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))
  • SA-2 Allocation of Resources
  • SA-5 System Documentation
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 9 controls

  • AT-2 Literacy Training and Awareness
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • IR-8 Incident Response Plan
  • PL-2 System Security and Privacy Plans
  • PL-4 Rules of Behavior
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))
  • SA-2 Allocation of Resources
  • SA-5 System Documentation
  • SR-1 Policy and Procedures (SR-1)

ISO/IEC 42001:2023 · 9 controls

  • 7.3 Awareness
  • 7.4 Communication
  • 7.5 Documented information
  • A.2.3 Alignment with other organizational policies
  • A.3.2 AI roles and responsibilities
  • A.3.3 Reporting of concerns
  • A.5.3 Documentation of AI system impact assessments
  • A.8.2 System documentation and information for users
  • A.9.3 Objectives for responsible use of AI system
  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents

ISO 22301:2019 · 8 controls

  • 4.2.1 General
  • 5.2.2 Communicating the business continuity policy
  • 5.3 Roles, responsibilities and authorities
  • 6.2.1 Establishing business continuity objectives
  • 7.3 Awareness
  • 7.4 Communication
  • 7.5.3 Control of documented information
  • 9.3.3 Management review outputs

ISO 27002:2022 · 8 controls

  • 5.1 Policies for information security
  • 5.10 Acceptable use of information and other associated assets
  • 5.2 Information security roles and responsibilities
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities
  • 6.2 Terms and conditions of employment
  • 6.3 Information security awareness, education and training
  • 6.5 Responsibilities after termination or change of employment

ISO 27001:2022 · 5 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.4 Management responsibilities
  • 6.2 Terms and conditions of employment
  • 6.3 Information security awareness, education and training

ISO 27701:2019 · 5 controls

  • 5.2 Context of the organization
  • 5.5.3 Awareness
  • 6.3 Organization of information security
  • 6.6.3 User responsibilities
  • 6.9.1 Operational procedures and responsibilities
  • CPS220-16 Management Information System and Data Framework
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements
  • CPS230-P23 Senior Management Information to the Board on Resilience Decisions

C5 (Germany) · 3 controls

  • C5-HR-03 Security training and awareness programme
  • C5-SIM-04 Duty of the users to report security incidents to a central body
  • C5-SP-01 Documentation, communication and provision of policies and instructions

HIPAA Security Rule · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

CMMC 2.0 · 2 controls

NIST SP 800-218 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-COMMS Communication
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice

APRA CPS 234 · 1 control

  • CPS234-P19 Policy Direction to All Responsible Parties
  • AUCDR-IS-6 Information security training and awareness program
  • AEO-10 Education, Training and Awareness
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

DORA · 1 control

EU AI Act · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC2.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 146 it maps to, and the evidence behind each claim, over MCP and REST.