07 - References and Further Reading
references-and-further-reading', 'appsec', 'security', 'compliance']
07 - References and Further Reading
To fully master SOC 2 and compliance engineering, consult the authoritative sources below.
🏛 Official Frameworks
- AICPA SOC 2 Guidelines The definitive source for the Trust Services Criteria (TSC) directly from the American Institute of CPAs.
- Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) A cybersecurity control framework for cloud computing. Excellent for mapping SOC 2 controls to technical implementations.
☁️ Cloud Provider Compliance Resources
- AWS SOC Compliance AWS Artifact allows you to download AWS's own SOC 2 report to inherit their physical security controls.
- Google Cloud SOC Reports Similar to AWS, download GCP's reports for your Vendor Management evidence.
- Azure SOC 2
📚 Security Tooling and Automation
- Vanta - Continuous compliance automation platform.
- Drata - Compliance and risk management OS.
- Secureframe - Automated SOC 2 and ISO 27001 compliance.
- Terraform AWS Provider - Infrastructure as Code documentation for automating compliant environments.
📖 Recommended Reading
- Engineering Compliance: The Developer's Guide to SOC 2 (Articles and blog series often published by engineering teams going through their first audit, e.g., on Medium or engineering blogs of companies like Segment, Stripe, or HashiCorp).