diff --git a/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md b/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md index d22a278ed..1977dafc3 100644 --- a/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md +++ b/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md @@ -11,20 +11,20 @@ frameworks: ## Purpose -Having clear ownership improve accountability, it helps employees -figure out what is legit and what is not. +Having clear ownership improve accountability, it helps employees figure out +what is legit and what is not. ## Implementation -Here is the kind of document expected - it has to be done for every -role with a potential impact on security: +Here is the kind of document expected - it has to be done for every role with a +potential impact on security: -| Role | Responsibilities | -|------|-----------------| -| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices
• Implements and enforces security policies across all engineering teams
• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management
• Coordinates the implementation of access controls, encryption protocols, and incident response procedures | -| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy
• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures
• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process
• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements | -| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems
• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control
• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements | -| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place
• Manages access for new joiners and leavers for all general software and platforms
• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles
• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data | +| Role | Responsibilities | +| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices
• Implements and enforces security policies across all engineering teams
• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management
• Coordinates the implementation of access controls, encryption protocols, and incident response procedures | +| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy
• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures
• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process
• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements | +| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems
• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control
• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements | +| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place
• Manages access for new joiners and leavers for all general software and platforms
• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles
• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data | ## Evidence