SOC 2 Starter: Logging, Access Controls & Change Management
- Logging: centralize app, infra, and auth logs; retain 1 year.
- Access: SSO, JIT elevation, quarterly reviews, offboarding SLAs.
- Change: code review required, CI attestations, emergency change log.
Link each control to evidence: dashboards, tickets, doc references.