Reliability, security & resilience · Working
SOC 2
Also called: System and Organization Controls 2
ELI5
An independent report on how a service organisation controls certain risks.
Used in conversation
“SOC 2 is an attestation report, not a permanent security guarantee.”
Definition
An attestation framework reporting on controls relevant to security, availability and other trust-service criteria.
Here “SOC 2” means: An attestation framework reporting on controls relevant to security, availability and other trust-service criteria.
Pitch context
You will see “SOC 2” in product strategy decks, roadmaps, experiments and architecture reviews when the discussion reaches reliability, security & resilience.
Why it matters: In reliability, security & resilience, the scope can change what data may be used, who may access it and which controls are required.
Sources & evidence · 2
Direct term-level sources and supporting source families.
- National Institute of Standards and Technology — Computer Security Resource Center GlossaryDirect source · primary · checked 2026-08-16
- Scrum Guides — The Scrum Guide — official current versionSupporting source family · primary · checked 2026-08-16