Skip to content

Compliance quick reference for SREs

First PublishedByAtif Alam

Use this page when you need a fast orientation: “We are in scope for X — what should I open or verify first?” It links outward; it does not replace your control register or auditor pack.

Not legal, audit, or compliance advice. Your GRC and legal owners define authoritative mappings and scope.

Rows are common regimes; columns are where SREs and platform teams usually spend time. Cells are starting points only.

ConcernSOC 2 (TSC-style)ISO 27001 (high level)HIPAA (technical ops angle)PCI DSS (pipeline / platform slice)CIS
Pipeline / changeCompliance and audit (SOC 2 table); Security scanningSame CI/CD evidence story; Policy as codeChange control + access to PHI paths; ComplianceBuild/deploy integrity, access to CDE-related automation; Artifact managementCIS controls and cloud benchmarks — secure config + change
Runtime / platformProduction platform checklist; PSSHardening, availability, loggingPHI systems segmentation awareness with platform; Network policies and TLS and certificates where applicableSegmentation, logging, patching discipline; Kubernetes troubleshootingSame CIS page + benchmarks for AWS/Azure
Identity & secretsAWS IAM, AWS secrets, Kubeconfig and authenticationAccess control evidenceMinimum necessary access, break-glass process with securityStrong auth for CI/CD and admins; secrets rotationIAM + secrets + Security scanning (secret detection)
Evidence & auditAudit fieldwork — walkthroughs, samplingSame page for ISO-style evidence patternsAudit trails, access reviews (coordinate with compliance)Evidence for changes touching CDE; ticketing + CI logsBenchmark reports + continuous assessment story
  • RBAC and cloud IAM — least privilege for humans and automation.
  • AWS secrets (or org secret store) — rotation and pipeline access patterns documented.
  • Audit fieldwork — Evidence types and walkthroughs (ISO overlaps heavily with SOC 2-style fieldwork in practice).
  • Compliance and audit — Change and access evidence from pipelines.
  • Observability — Logging and retention aligned to policy.

HIPAA — quick checks (technical / ops angle only)

Section titled “HIPAA — quick checks (technical / ops angle only)”