Commitment to integrity and ethical values is demonstrated
The organization sets the tone for security through visible leadership behaviour and documented ethical standards. Auditors look for evidence that integrity is not just stated but actively modelled. This means a code of conduct that employees sign, clear consequences when it is violated, and leadership that visibly follows the same rules. Without this, every other control is built on a weak foundation.
Implementation steps
- 1
Publish a code of conduct and ethics policy
Write a code of conduct that covers conflicts of interest, data handling, acceptable use, and reporting of violations. Have legal review it. Publish it somewhere all employees can access it and ensure it is referenced in offer letters and employment agreements.
confluence notion google-docs - 2
Require acknowledgment at onboarding and annually
Every employee should sign or digitally acknowledge the code of conduct when they join and once per year. Track completions. If someone refuses to acknowledge, that is itself a finding.
rippling workday bamboohr docusign - 3
Establish a confidential reporting mechanism
Provide a way for employees to report suspected violations without fear of retaliation. This can be as simple as a dedicated email alias reviewed by legal or HR, or a third-party ethics hotline for larger organizations. Document that the channel exists and that reports are acted upon.
ethicspoint convercent bamboohr
Evidence required
Code of conduct or ethics policy
A written, approved, and accessible document covering integrity standards, conflicts of interest, and acceptable behaviour.
- - Code of conduct published on internal wiki with approval date
- - Employee handbook section on ethics signed by CEO
- - Acceptable use policy referenced in employment agreements
Employee acknowledgment records
Evidence that all employees have acknowledged the code of conduct.
- - HRIS report showing acknowledgment completion per employee
- - DocuSign envelope records for annual policy review
- - LMS completion log for ethics training module
Related controls
Board or equivalent body oversees security risk
Control Environment
Organizational structure and authority for security is defined
Control Environment
Commitment to competence in security is demonstrated
Control Environment
Accountability for security performance is enforced
Control Environment