SOC 2 from the DevOps Angle: Why Your Infrastructure Engineer Is Your Best Compliance Lead
When leadership announced we were pursuing SOC2, the first idea was the same every company has: hire a compliance consultant. Still, as a DevOps Engineer, I realised straight away that almost every control the auditor or readiness consultant were going to ask about lived in systems I already owned.
Access reviews? That’s our IAM and authentication directory. Change management? It lives in our CI/CD. Encryption at rest and in transit is reflected across our networking and configuration management. Logging and monitoring? Our observability stack. Vulnerability management? Already was on my plate as the common security exercise.
So instead of assisting in SOC2, I decided to own it. And this is the story of taking a company with hybrid infrastructure through a full SOC2 Type II audit, and why I’ve come to believe DevOps is the most viable owner and facilitator for this journey, not just a contributor to it.
SOC...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE