<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SOC 2 on pyToshka's DevSecOps Blog</title><link>https://blog.pytoshka.me/en/tags/soc-2/</link><description>Recent content in SOC 2 on pyToshka's DevSecOps Blog</description><generator>Hugo</generator><language>en-US</language><managingEditor>ping@pytoshka.me (pyToshka)</managingEditor><webMaster>ping@pytoshka.me (pyToshka)</webMaster><lastBuildDate>Mon, 23 Mar 2026 21:09:47 +0400</lastBuildDate><atom:link href="https://blog.pytoshka.me/en/tags/soc-2/index.xml" rel="self" type="application/rss+xml"/><item><title>Amazon EKS SOC 2 Type II Compliance Checklist part 1</title><link>https://blog.pytoshka.me/en/post/amazon-eks-soc2-type-ii-compliance-checklist-part-1/</link><pubDate>Tue, 29 Jul 2025 00:00:00 +0000</pubDate><author>ping@pytoshka.me (pyToshka)</author><guid>https://blog.pytoshka.me/en/post/amazon-eks-soc2-type-ii-compliance-checklist-part-1/</guid><description>&lt;h2 id="introduction"&gt;
 Introduction
 &lt;a class="header-anchor" href="#introduction" aria-label="Permalink to this section"&gt;
 &lt;svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg"&gt;
 &lt;path d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.65 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z" fill="currentColor"/&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Navigating the world of compliance can feel like trying to read a map in a language you don&amp;rsquo;t speak. When you throw Kubernetes into the mix, it gets even trickier. That&amp;rsquo;s why we&amp;rsquo;ve put together this straightforward, human-friendly checklist to help you get your Amazon EKS clusters ready for a SOC 2 Type II audit.&lt;/p&gt;</description></item><item><title>Amazon EKS SOC 2 Type II Compliance Checklist part 2</title><link>https://blog.pytoshka.me/en/post/amazon-eks-soc2-type-ii-compliance-checklist-part-2/</link><pubDate>Tue, 29 Jul 2025 00:00:00 +0000</pubDate><author>ping@pytoshka.me (pyToshka)</author><guid>https://blog.pytoshka.me/en/post/amazon-eks-soc2-type-ii-compliance-checklist-part-2/</guid><description>&lt;p&gt;Moving on, let&amp;rsquo;s look at the other controls for EKS SOC Type 2.&lt;/p&gt;
&lt;p&gt;For container security best practices, see our guide on &lt;a href="https://blog.pytoshka.me/en/post/container-image-security-with-wazuh-and-trivy/"&gt;Container Image Security with Wazuh and Trivy&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="cc3-risk-assessment"&gt;
 CC3: Risk Assessment
 &lt;a class="header-anchor" href="#cc3-risk-assessment" aria-label="Permalink to this section"&gt;
 &lt;svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg"&gt;
 &lt;path d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.65 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z" fill="currentColor"/&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;hr&gt;
&lt;h3 id="eks-specific-risk-assessment"&gt;
 EKS-Specific Risk Assessment
 &lt;a class="header-anchor" href="#eks-specific-risk-assessment" aria-label="Permalink to this section"&gt;
 &lt;svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg"&gt;
 &lt;path d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.65 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z" fill="currentColor"/&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
&lt;/h3&gt;&lt;p&gt;Identify, evaluate, and document security, operational, and compliance risks specific to Amazon EKS clusters and workloads to ensure that appropriate controls are implemented, monitored, and improved in alignment with SOC 2 Trust Services Criteria.&lt;/p&gt;</description></item></channel></rss>