SOC 2 policies for AWS teams

AWS hosts your production environment, so it appears wherever the policies talk about who can reach production, how data is encrypted, what is logged, how services recover and how the network is segmented.

Cloud platforms · Referenced by 6 of 22 policies · Generator preset available

The 6 policies that reference AWS

With AWS in your intake, these policies name it in their scope, roles and procedures. The other 16 policies in the set apply to your company regardless of tooling; the template index lists all 22.

  • P03 Access Control Policy: Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
  • P08 Encryption and Key Management Policy: Sets minimum encryption standards for data in transit and at rest and defines how cryptographic keys, secrets and certificates are generated, stored, rotated and retired.
  • P12 Logging and Monitoring Policy: Defines which security-relevant events are logged across the product, cloud and corporate systems, how logs are protected and retained, and how alerts are triaged and acted on.
  • P14 Business Continuity and Disaster Recovery Policy: Sets recovery objectives by system tier, defines how a disaster is declared and recovered from, and requires the plan to be tested and maintained.
  • P15 Backup and Recovery Policy: Requires every data set that supports the product and the business to be backed up on a defined schedule, protected, monitored and proven restorable through regular tests.
  • P20 Network and Infrastructure Security Policy: Defines how the cloud networks, compute and supporting infrastructure behind the product are segmented, hardened, administered and monitored.

What the Audit Kit writes for AWS

The free generator fills in names. The Audit Kit goes further: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy using your full intake, so the text describes AWS the way you actually run it. The statements below are examples of that output for AWS; your own answers produce different text, and every statement should be checked against your configuration before management adopts it.

P03 Access Control Policy

Human access to AWS is granted only through AWS IAM Identity Center permission sets assigned to groups synchronised from the identity provider, with a session duration of no more than eight hours. IAM users with long-lived access keys are prohibited for people, and the IAM credential report is reviewed at each quarterly access review to confirm that none exist.

P08 Encryption and Key Management Policy

Every S3 bucket has default encryption set to SSE-KMS with a customer-managed key, and EBS encryption by default and RDS storage encryption are enabled in every region in use. KMS keys have automatic annual rotation enabled, and key policies restrict kms:ScheduleKeyDeletion and key policy changes to the security administrator role.

P12 Logging and Monitoring Policy

A CloudTrail organization trail records management events from every account and region into an S3 bucket in a dedicated log-archive account, with log file validation, S3 Object Lock and a 400-day retention lifecycle. GuardDuty and AWS Config are enabled in every region, and GuardDuty findings of High severity are routed to the incident channel through EventBridge within five minutes.

P14 Business Continuity and Disaster Recovery Policy

Production services run across at least two Availability Zones behind an Application Load Balancer with health checks, and RDS instances use Multi-AZ deployments. The disaster recovery runbook names the recovery region, the cross-region backup copies it restores from, and the most recently tested recovery time and recovery point objectives.

P15 Backup and Recovery Policy

AWS Backup plans take daily snapshots of every RDS, DynamoDB and EBS resource tagged Backup=production, copy them to a backup vault in a second region protected by AWS Backup Vault Lock, and retain them for 35 days. A restore of the production database into an isolated account is performed and documented quarterly.

P20 Network and Infrastructure Security Policy

Production workloads run in private subnets without public IP addresses, reach AWS services through VPC endpoints, and accept inbound traffic only from the load balancer security group. VPC Flow Logs are enabled on every VPC, and AWS Config managed rules alert on any security group that allows 0.0.0.0/0 ingress on a port other than 443.

How to use this page

  1. Open the generator with the AWS preset and answer the remaining questions: company, product, headcount, other tools, data types, owners, scope and review cadence.
  2. Download the 22 policies as Markdown. Read the sections that mention AWS with the admin console open and fix anything that is not true of your setup.
  3. Optionally buy the Audit Kit to have sections 4 and 5 tailored to AWS and the rest of your stack, and to get Word documents, the TSC crosswalk, an evidence checklist, acknowledgment forms and a review calendar in one ZIP built on your machine.
  4. Have management approve the policies, collect acknowledgments, and start producing the evidence the procedures describe. The CPA firm performs the examination.

Other tools

Cloud platforms: Google Cloud, Microsoft Azure, Vercel, Cloudflare

Source control and CI: GitHub, GitLab

Identity providers: Google Workspace, Okta, Microsoft 365

Vendors and subprocessors: Supabase, Clerk

Frequently asked questions

Does AWS's SOC 2 report cover our own SOC 2?
No. AWS's own SOC 2 report covers the controls AWS operates for its platform. Your examination covers how your company configures and uses AWS: who has access, how it is authenticated, what is logged and how data in it is protected. Auditors read the vendor's report to decide what they can rely on, and the Vendor and Third-Party Risk Management Policy tells you to collect it at onboarding and annually.
What does the generator pre-fill when I arrive from this page?
The link on this page opens the generator with a preset that sets the cloud platform to AWS. The other answers (company, product, headcount, owners, data types, scope and review cadence) are yours to fill in. The policies render in your browser as Markdown; nothing is sent to a server and there is no signup.
Which policies change when I add AWS to my answers?
6 policies name AWS once it is in the intake: Access Control Policy, Encryption and Key Management Policy, Logging and Monitoring Policy, Business Continuity and Disaster Recovery Policy, Backup and Recovery Policy, Network and Infrastructure Security Policy. The free generator names it in scope, roles and procedures; the Audit Kit ($39 one-time) rewrites sections 4 and 5 of each policy with statements specific to how AWS is configured, like the examples on this page. Refunds are available within 14 days on request.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.