SOC 2 · CC1

CC1 · Control Environment

5 controls in this family.

preventivemedium
Adopt

Code of Conduct and Ethics Policy

Formal policy establishing expected standards of ethical behavior, conflicts of interest, and disciplinary consequences for all employees and contractors.

CC1.1CC1.2

Testing: Annually

preventivemedium
Adopt

Organizational Structure and Accountability

Documented org chart with clear reporting lines, defined roles, and delegated authority for security and compliance responsibilities.

CC1.3

Testing: Annually

preventivemedium
Adopt

Employee Background Check Process

Pre-employment background screening for all employees and contractors with access to customer data or production systems.

CC1.4

Testing: Per hire

preventivelow
Adopt

Performance Management and Competency Assessment

Formal process for evaluating employee performance, identifying skills gaps, and ensuring staff have the competencies required for their security-relevant roles.

CC1.4CC1.5

Testing: Annually

preventivemedium
Adopt

Security Awareness Training

Annual security awareness training for all employees covering phishing, social engineering, password hygiene, and data handling responsibilities.

CC1.4CC2.2CC5.3

Testing: Annually