Remap categories

Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-14 11:34:46 +01:00
parent 77b6a273cb
commit 15c6902c13
15 changed files with 62 additions and 24 deletions

View File

@@ -1,14 +1,17 @@
---
id: "PLT-EMAIL-001"
category: "platform/email-security"
id: "PER.COM.001"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC6.1", "CC6.8"]
---
# Configure SPF for Email Authentication
## Purpose
SPF (Sender Policy Framework) prevents email spoofing by defining which mail

View File

@@ -1,14 +1,17 @@
---
id: "PLT-EMAIL-002"
category: "platform/email-security"
id: "PER.COM.002"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC6.1", "CC6.8"]
---
# Configure DKIM for Email Authentication
## Purpose
DKIM (DomainKeys Identified Mail) helps prevent email spoofing by adding a

View File

@@ -1,19 +1,22 @@
---
id: "PLT-EMAIL-003"
category: "platform/email-security"
id: "PER.COM.003"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "30m"
necessity: "mandatory"
related:
- id: "COM-EMAIL-001"
- id: "PER.COM.001"
required: true
- id: "COM-EMAIL-002"
- id: "PER.COM.002"
required: true
frameworks:
- name: "soc2"
sections: ["CC6.1", "CC6.8"]
---
# Configure DMARC for Email Authentication
## Purpose
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a

View File

@@ -1,14 +1,17 @@
---
id: "PLT-EMAIL-004"
category: "platform/email-security"
id: "PER.COM.004"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC6.8", "CC7.2"]
---
# Configure Email Security Filters
## Purpose
Implement email filtering and warning systems to reduce phishing risks and

View File

@@ -1,14 +1,17 @@
---
id: "ACC-IDM-001"
category: "access/identity-management"
id: "PER.LIF.001"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.3"]
---
# Integrate security checklist in your onboarding process
## Purpose
It is the perfect timing to ensure that every employees has:
@@ -20,7 +23,7 @@ It is the perfect timing to ensure that every employees has:
## Implementation
In theory, you already have an onboarding plan for your new employees (if not,
Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for
[Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for
your admin running the onboarding (if not,
[Onboarding admin checklist](templates/onboarding-admin-checklist.md)).
@@ -41,3 +44,4 @@ On your admin to-do, be sure to include:
## Evidence
- Screenshots of a completed onboarding checklists.
- Screenshots of a completed admin checklist for new joiner.

View File

@@ -1,14 +1,17 @@
---
id: "ACC-IDM-002"
category: "access/identity-management"
id: "PER.LIF.002"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC5.3", "CC6.2", "CC6.5"]
---
# Properly off-board your employees
## Purpose
Yes, people will leave your company (either by your decision or theirs). And you
@@ -30,3 +33,7 @@ they left!
[Offboarding admin checklist](templates/offboarding-admin-checklist.md))
2. Upload a screenshot of your checklist that contains those bullet points below
## Evidence
- Screenshot of a completed admin checklist for offboarding

View File

@@ -1,14 +1,17 @@
---
id: "ACC-IDM-003"
category: "access/identity-management"
id: "PER.LIF.003"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.3"]
---
# Know your recruits
## Purpose
When recruiting someone, you want to be sure of who you are hiring: by

View File

@@ -1,14 +1,17 @@
---
id: "OPS-REP-001"
category: "operations/reporting"
id: "PER.LIF.004"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC2.2"]
---
# Implement confidential whistleblower process
## Purpose
It encourages and enables employees to raise serious concerns (violations of

View File

@@ -1,14 +1,17 @@
---
id: "OPS-REP-002"
category: "operations/reporting"
id: "PER.LIF.005"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "30m"
necessity: "optional"
frameworks:
- name: "soc2"
sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"]
---
# Run performance reviews
## Purpose
Makes sure your team has the skills and focus needed to protect what matters

View File

@@ -1,14 +1,17 @@
---
id: "OPS-REP-003"
category: "operations/reporting"
id: "PER.LIF.006"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
---
# Specify security responsabilities
## Purpose
Having clear ownership improve accountability, it helps employees figure out

View File

@@ -1,14 +1,17 @@
---
id: "OPS.TRN-001"
id: "PER.LIF.007"
category: "operations/training"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "30m"
necessity: "optional"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC2.2"]
---
# Train your employees on security
## Purpose
Your employees are the main target of cyber threats (especially phishing and