MCMMCM DocsEngineering (Internal)
HLDModulesGovernanceBuilt-in Groups
v1.2 is unreleased — see v1.1 for the current stable release.

SOC 2 Compliance

SOC 2 Trust Service Criteria, cloud enforcement, and control coverage mapping.

SOC 2 Compliance

SOC 2 (System and Organization Controls Type II) is a security and compliance framework developed by the AICPA that evaluates how organisations protect customer data over time. It is widely used by SaaS, cloud-native, and service organisations to demonstrate trust to customers.

SOC 2 evaluates operational effectiveness of controls over an audit period (typically 3–12 months) — not just their design.


Trust Service Criteria (TSC)

A. Security (Mandatory)

  • Logical and physical access controls.
  • System monitoring and logging.
  • Risk mitigation and vulnerability management.

B. Availability

  • System uptime and resilience.
  • Backup and disaster recovery.

C. Processing Integrity

  • Data accuracy, completeness, and validity.
  • Change management.

D. Confidentiality

  • Data classification.
  • Encryption and access restrictions.

E. Privacy (Optional)

  • Personal data handling.
  • Retention and disposal.

SOC 2 Type II evaluates design + operating effectiveness over a period of 3–12 months. Point-in-time checks alone are insufficient.


What SOC 2 Requires in Cloud Environments

  • Strong IAM and access governance.
  • Encryption for all data at rest and in transit.
  • Continuous logging and monitoring.
  • Vulnerability and malware detection.
  • Secure configuration baselines (CIS-style guardrails).
  • Change management evidence.
  • Incident response readiness.

Full Controls Coverage

SOC 2 Control / RequirementTool CoverageNotes
IAM least privilegeCloud CustodianPolicy hygiene and role enforcement
MFA enforcementCloud CustodianIAM credential controls
Access review automationCloud CustodianDetect unused / over-privileged access
Encryption at restCloud CustodianS3, EBS, RDS encryption checks
Encryption in transitCloud CustodianTLS / HTTPS enforcement
Public cloud resource exposureCloud CustodianPrevents accidental data exposure
Secure cloud configuration baselinesCloud CustodianCIS-style guardrails
Cloud audit logging enabledCloud CustodianCloudTrail / Activity logs
Log collection (OS & application)WazuhCentralised host-level logs
Log integrity monitoringWazuhDetects tampering
File integrity monitoring (FIM)WazuhRequired for Security TSC
Malware detectionWazuhHost-based threat detection
Intrusion detectionWazuhRuntime security monitoring
Vulnerability scanningWazuhCVE detection on hosts
Configuration drift detection (OS)WazuhDetects unauthorised changes
Incident detection & alertingWazuhSecurity event alerts
Incident investigation evidenceWazuhTimelines and artefacts
Backup enforcementCloud CustodianSnapshot / backup policies
DR readiness validationRequires architecture & testing
Change management approvalProcess + ticketing
Secure SDLC controlsCI/CD & governance process
Vendor risk managementGRC process
Security policies & proceduresDocumentation requirement
Employee security trainingHR & governance
Privacy notice & consent (if in scope)Legal & application-level

On this page