CC1.1: Integrity and ethical values
Leadership sets a clear expectation of honest, ethical behavior, writes it down, and holds everyone (including contractors) to it.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC1 (Control environment) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC1.1
The Policyseed crosswalk points CC1.1 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P01 Information Security Policy, section 4 (Policy Statements). Owner: Security Owner.
- P02 Acceptable Use Policy, section 4 (Policy Statements). Owner: Security Owner.
- P18 Human Resources Security Policy, section 4 (Policy Statements). Owner: People/HR Lead.
Evidence examples for CC1.1
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Signed Acceptable Use Policy acknowledgment forms for every employee and contractor
- Employee handbook or code of conduct section referenced by the Information Security Policy
- Approved Information Security Policy with the approver's name and effective date on the revision table
Related criteria in CC1 (Control environment)
- CC1.2: Oversight by leadership
- CC1.3: Structure, reporting lines and authority
- CC1.4: Competent people
- CC1.5: Accountability
Next: CC1.2 Oversight by leadership. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.