SOC 2 Compliance Guide
📖 Overview
Welcome to the AppSec Atlas SOC 2 Compliance Guide. SOC 2 (System and Organization Controls 2) is a compliance framework designed by the AICPA to ensure service organizations securely manage data to protect the interests of their organization and the privacy of their clients.
🎯 Learning Objectives
By the end of this guide, you will:
- Understand the difference between SOC 2 Type 1 and Type 2.
- Master the 5 Trust Services Criteria (TSC) with a focus on Security (Common Criteria).
- Automate evidence collection across AWS, GitHub, and Datadog.
- Develop standard organizational policies required for SOC 2.
- Integrate continuous compliance tools (Vanta, Drata).
- Build a hands-on Python lab for automated evidence collection.
⚙️ Prerequisites
- Basic understanding of cloud infrastructure (AWS/GCP/Azure).
- Familiarity with CI/CD and Version Control (GitHub, GitLab).
- Experience with Python (for automation labs).
- Knowledge of basic security principles (IAM, least privilege, encryption).
🧭 Navigation
- 01 Introduction - SOC 2 Type 1 vs Type 2, Trust Services Criteria.
- 02 Trust Services Criteria Deep Dive - Common Criteria, Access Controls, Change Management.
- 03 Evidence Collection and Auditing - Automated evidence collection scripts.
- 04 SOC 2 Policy Templates - Information Security, Access Control, IR, Vendor Management.
- 05 Continuous Compliance - Using Vanta, Drata, and Secureframe.
- 06 Hands-on Lab - Python evidence collector and compliance checker.
- 07 References - AICPA guidelines, CSA CCM, AWS compliance.