CC2.2: Internal communication

Staff know the security policies that apply to them, how to report a problem, and what their responsibilities are, because the company tells them at hire and on an ongoing basis.

Category: Security (common criteria, required in every SOC 2 report) · Series: CC2 (Communication and information) · TSC 2017 (2022 points of focus)

That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.

Policies that address CC2.2

The Policyseed crosswalk points CC2.2 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.

Evidence examples for CC2.2

Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.

  • Onboarding checklist showing policy distribution and security training as required steps
  • Signed policy acknowledgment forms for every active employee
  • Screenshot of the internal incident reporting channel or address referenced in the Incident Response Policy
  • Announcement to staff when a policy is updated (email or chat message with date)

Related criteria in CC2 (Communication and information)

Previous: CC2.1 Quality information. Next: CC2.3 External communication. All 38 criteria are listed on the template index.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.