C1.1: Identifying and protecting confidential information
The company defines what counts as confidential, labels or classifies it, and applies handling and retention rules so it stays protected for as long as it is kept.
Category: Confidentiality (optional category) · Series: C1 (Confidentiality) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address C1.1
The Policyseed crosswalk points C1.1 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P06 Data Classification and Handling Policy, section 4 (Policy Statements). Owner: Security Owner.
- P07 Data Retention and Disposal Policy, section 4 (Policy Statements). Owner: Security Owner.
- P22 Privacy and Data Protection Policy, section 4 (Policy Statements). Owner: Security Owner.
Evidence examples for C1.1
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Data classification matrix listing the classification levels and handling rules for each
- Data inventory or data map showing where confidential and personal data is stored
- Retention schedule listing each data category and its retention period
- Sample customer contract confidentiality clause
Related criteria in C1 (Confidentiality)
Previous: A1.3 Recovery testing. Next: C1.2 Disposing of confidential information. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.