Protecting customer data depends on more than technical safeguards. An organization also needs clear responsibilities, ethical leadership, and oversight that holds decision-makers accountable.
CC1, the Control Environment group within the SOC 2 common criteria, addresses this organizational foundation. It covers the values, governance, structure, and competence that support internal controls: the policies and procedures an organization uses to manage risk and achieve its objectives.
A written policy needs people who understand it and act on it. A security tool needs an owner who can make decisions and fix problems. CC1 helps a company build that base.
For example, a team may have a process to remove access when someone leaves. That process is easier to maintain when HR knows who to notify, IT knows what to remove, and a leader checks that the work was done. Clear roles connect the policy to daily work.
The following descriptive headings summarize the five CC1 criteria; they are editorial labels, not official AICPA titles:
These summaries provide an introduction to the requirements. See the AICPA Trust Services Criteria for the complete criteria and related points of focus.
Customers reviewing a SOC 2 report need to understand the organizational practices supporting the controls described in it. CC1-related controls can help them assess several important questions:
Supporting evidence may include training records, documented responsibilities, board meeting records, and corrective-action follow-up. The appropriate evidence depends on the controls implemented and the activities those controls require.
CC1 should be considered alongside the rest of the SOC 2 report, including its scope, reporting dates, auditor’s opinion, and any reported exceptions. A testing exception indicates a departure from the expected operation of a control; its significance depends on the circumstances and the report as a whole.
A Type 2 examination addresses the suitability of control design and operating effectiveness over a specified period, and the report includes the auditor’s tests and results. A Type 1 examination addresses control design as of a specified date, without an opinion on operating effectiveness over time. The AICPA explains this distinction in its Trust Services Criteria. Neither report guarantees that future incidents will be prevented.
Organizations can address the same criteria through different control designs. The following examples illustrate approaches to discuss with your auditor:
Headcount is only one consideration. Risk exposure, organizational structure, and the services provided also influence the appropriate approach. Small organizations still need to address the applicable criteria, including appropriate oversight.
The articles below will examine each criterion in greater detail, with practical control and evidence examples for organizations of different sizes.
Discuss your SOC 2 objectives with Genius GRC and identify controls and supporting evidence appropriate to your organization’s risks, responsibilities, and resources.