Subsystem 01
Identity & single sign-on
Okta or Google Workspace SSO with hardware-key MFA and short-lived IAM roles
Typical stack
AWS IAM Identity Center
Reference architecture
A Terraform-managed AWS baseline that collects control evidence automatically. We prepare the evidence; the audit opinion is issued by your independent CPA firm.
Design constraints
Targets for the scenario this reference is sized for. A real engagement starts by replacing them with your own numbers.
Component topology
Subsystems with separate responsibilities, clear contracts between them and storage that scales on its own. The stack named for each is typical, not mandatory.
Stack topology
SOC 2 Type 2 readiness architecture on AWS
Illustrative reference architecture
Identity & single sign-on
Okta or Google Workspace SSO with hardware-key MFA and short-lived IAM roles
AWS IAM Identity Center
Continuous compliance monitoring
Misconfiguration detection and evidence reporting
AWS Config + Vanta / Drata
Vulnerability & threat detection
Runtime anomaly detection and container image scanning
Amazon GuardDuty + Amazon Inspector
Centralized audit trail
Write-once audit logging aggregated across accounts
AWS CloudTrail + S3 Object Lock
Subsystem 01
Okta or Google Workspace SSO with hardware-key MFA and short-lived IAM roles
Typical stack
AWS IAM Identity Center
Subsystem 02
Misconfiguration detection and evidence reporting
Typical stack
AWS Config + Vanta / Drata
Subsystem 03
Runtime anomaly detection and container image scanning
Typical stack
Amazon GuardDuty + Amazon Inspector
Subsystem 04
Write-once audit logging aggregated across accounts
Typical stack
AWS CloudTrail + S3 Object Lock
Data lifecycle
An engineer requests AWS access through Okta SSO and receives a one-hour IAM session.
CloudTrail logs every API call and infrastructure change to an S3 bucket in an isolated security account.
AWS Config evaluates resource changes against CIS AWS Foundations Benchmark rules.
A compliance platform (Vanta or Drata) gathers evidence from AWS APIs continuously.
GuardDuty findings trigger PagerDuty alerts and automated remediation Lambdas.
Reliability and resilience
Failure mode 01
Mitigation
Enable S3 Block Public Access at the organization root, backed by restrictive SCPs.
Failure mode 02
Mitigation
AWS Config auto-remediation rules quarantine unencrypted EBS volumes and databases as soon as they appear.
Failure mode 03
Mitigation
Quarterly access reviews generated from IdP and AWS SSO logs by a scheduled GitHub Actions workflow.
Questions
It depends on how many controls you already run. The infrastructure baseline can usually be codified in weeks; the Type 2 observation period is agreed with your auditor and commonly runs 3 to 12 months. We prepare the evidence; the audit opinion is issued by your independent CPA firm.
Type 1 evaluates whether your controls are designed properly on a specific date. Type 2 evaluates whether they operated effectively over an observation period, typically 3 to 12 months.
Send us your requirements, expected load and budget. We'll reply within one business day with an honest read on the design, and on whether we're the right team to build it.