# soc2

SOC 2 is an independent examination and attestation framework for evaluating controls over information systems, including security, availability, processing integrity, confidentiality, and privacy.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How to Achieve SOC2 Compliance for Teleport Cloud with Teleport On-Prem

DevFeed: [How to Achieve SOC2 Compliance for Teleport Cloud with Teleport On-Prem](<https://devfeed.tech/articles/how-to-achieve-soc2-compliance-for-teleport-cloud-with-teleport-on-prem-29911.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-cloud-soc2-compliance/>)

Author: info@goteleport.com (Travis Gary)

Published: 2021-08-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc2](<https://devfeed.tech/topics/soc2.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Security](<https://devfeed.tech/topics/security.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [okta](<https://devfeed.tech/topics/okta.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [applications](<https://devfeed.tech/tags/applications.md>), [audit](<https://devfeed.tech/tags/audit.md>), [availability](<https://devfeed.tech/tags/availability.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [developers](<https://devfeed.tech/tags/developers.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [jira](<https://devfeed.tech/tags/jira.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [okta](<https://devfeed.tech/tags/okta.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [pagerduty](<https://devfeed.tech/tags/pagerduty.md>), [platform](<https://devfeed.tech/tags/platform.md>), [soc2](<https://devfeed.tech/tags/soc2.md>)

### AI overview

This blog post explains how Teleport says it uses Teleport Cloud and Teleport On-Prem to support SOC2 compliance. It describes access controls, SSO integration, audit capabilities, approval workflows, Terraform-based change management, short-lived SSH certificates, and automated user lifecycle changes through Okta.

### Source excerpt

In this blog post we illustrate how we use Teleport to achieve SOC2 compliance at Teleport

## Teleport 5.0 Press Release

DevFeed: [Teleport 5.0 Press Release](<https://devfeed.tech/articles/teleport-5-0-press-release-29903.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-5-press-release/>)

Author: info@goteleport.com (Teleport Team)

Published: 2020-11-19T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [audit](<https://devfeed.tech/topics/audit.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Kubernetes clusters](<https://devfeed.tech/topics/kubernetes-clusters.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [soc2](<https://devfeed.tech/topics/soc2.md>)

Tags: [announcement](<https://devfeed.tech/tags/announcement.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [developer-productivity](<https://devfeed.tech/tags/developer-productivity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes-clusters](<https://devfeed.tech/tags/kubernetes-clusters.md>), [logging](<https://devfeed.tech/tags/logging.md>), [platform](<https://devfeed.tech/tags/platform.md>), [press-release](<https://devfeed.tech/tags/press-release.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Gravitational announced its rebrand to Teleport and launched the Teleport Access Platform. The platform consolidates access controls, auditing, and compliance across infrastructure, applications, and data, including servers and Kubernetes clusters, using SSO and short-lived certificates.

### Source excerpt

Teleport is the First Platform to Consolidate Access, Audit, and Compliance Across All Environments

## Seven Practices to Prepare a Startup for SOC 2

DevFeed: [Seven Practices to Prepare a Startup for SOC 2](<https://devfeed.tech/articles/the-soc2-starting-seven-29174.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2020/03/12/soc2-starting-seven/>)

Published: 2020-03-12T17:49:00Z

Content type: tutorial

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [soc2](<https://devfeed.tech/topics/soc2.md>), [Security](<https://devfeed.tech/topics/security.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Google Cloud Identity](<https://devfeed.tech/topics/google-cloud-identity.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [protected branches](<https://devfeed.tech/topics/protected-branches.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloudtrail](<https://devfeed.tech/tags/cloudtrail.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [github](<https://devfeed.tech/tags/github.md>), [logging](<https://devfeed.tech/tags/logging.md>), [okta](<https://devfeed.tech/tags/okta.md>), [patches](<https://devfeed.tech/tags/patches.md>), [protected-branches](<https://devfeed.tech/tags/protected-branches.md>), [security](<https://devfeed.tech/tags/security.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

The article recommends seven practices for startups that expect large-company clients to require a SOC 2 report: centralized identity with 2FA, pull-request controls and CI/CD, centralized logging, infrastructure provisioning with Terraform or a similar tool, AWS CloudTrail and AssumeRole, device management with encryption and current patches, and software vendor risk tracking. It also recommends documenting basic policies.

### Source excerpt

So, you plan to sell your startup's product to big companies one day. Congratu-dolences! Really, that's probably the only reason you should care about this article. If that's not you, go forth and live your life! We'll ask no more of your time. For the rest of you: Industry people talk about SOC2 a lot, and it's taken on a quasi-mystical status, not least because it's the product of the quasi-mystical accounting industry. But what it all boils down to is: eventually you'll run into big-company clients demanding a SOC2 report to close a sale. You know this and worry about it.