@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "PLT-EMAIL-001"
|
||||
category: "platform/email-security"
|
||||
id: "PER.COM.001"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.8"]
|
||||
---
|
||||
|
||||
# Configure SPF for Email Authentication
|
||||
|
||||
## Purpose
|
||||
|
||||
SPF (Sender Policy Framework) prevents email spoofing by defining which mail
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "PLT-EMAIL-002"
|
||||
category: "platform/email-security"
|
||||
id: "PER.COM.002"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.8"]
|
||||
---
|
||||
|
||||
# Configure DKIM for Email Authentication
|
||||
|
||||
## Purpose
|
||||
|
||||
DKIM (DomainKeys Identified Mail) helps prevent email spoofing by adding a
|
||||
@@ -1,19 +1,22 @@
|
||||
---
|
||||
id: "PLT-EMAIL-003"
|
||||
category: "platform/email-security"
|
||||
id: "PER.COM.003"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
related:
|
||||
- id: "COM-EMAIL-001"
|
||||
- id: "PER.COM.001"
|
||||
required: true
|
||||
- id: "COM-EMAIL-002"
|
||||
- id: "PER.COM.002"
|
||||
required: true
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.8"]
|
||||
---
|
||||
|
||||
# Configure DMARC for Email Authentication
|
||||
|
||||
## Purpose
|
||||
|
||||
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "PLT-EMAIL-004"
|
||||
category: "platform/email-security"
|
||||
id: "PER.COM.004"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.8", "CC7.2"]
|
||||
---
|
||||
|
||||
# Configure Email Security Filters
|
||||
|
||||
## Purpose
|
||||
|
||||
Implement email filtering and warning systems to reduce phishing risks and
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "ACC-IDM-001"
|
||||
category: "access/identity-management"
|
||||
id: "PER.LIF.001"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-10"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC5.3"]
|
||||
---
|
||||
|
||||
# Integrate security checklist in your onboarding process
|
||||
|
||||
## Purpose
|
||||
|
||||
It is the perfect timing to ensure that every employees has:
|
||||
@@ -20,7 +23,7 @@ It is the perfect timing to ensure that every employees has:
|
||||
## Implementation
|
||||
|
||||
In theory, you already have an onboarding plan for your new employees (if not,
|
||||
Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for
|
||||
[Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for
|
||||
your admin running the onboarding (if not,
|
||||
[Onboarding admin checklist](templates/onboarding-admin-checklist.md)).
|
||||
|
||||
@@ -41,3 +44,4 @@ On your admin to-do, be sure to include:
|
||||
## Evidence
|
||||
|
||||
- Screenshots of a completed onboarding checklists.
|
||||
- Screenshots of a completed admin checklist for new joiner.
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "ACC-IDM-002"
|
||||
category: "access/identity-management"
|
||||
id: "PER.LIF.002"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-10"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC5.3", "CC6.2", "CC6.5"]
|
||||
---
|
||||
|
||||
# Properly off-board your employees
|
||||
|
||||
## Purpose
|
||||
|
||||
Yes, people will leave your company (either by your decision or theirs). And you
|
||||
@@ -30,3 +33,7 @@ they left!
|
||||
[Offboarding admin checklist](templates/offboarding-admin-checklist.md))
|
||||
|
||||
2. Upload a screenshot of your checklist that contains those bullet points below
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of a completed admin checklist for offboarding
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "ACC-IDM-003"
|
||||
category: "access/identity-management"
|
||||
id: "PER.LIF.003"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-10"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC5.3"]
|
||||
---
|
||||
|
||||
# Know your recruits
|
||||
|
||||
## Purpose
|
||||
|
||||
When recruiting someone, you want to be sure of who you are hiring: by
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "OPS-REP-001"
|
||||
category: "operations/reporting"
|
||||
id: "PER.LIF.004"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC2.2"]
|
||||
---
|
||||
|
||||
# Implement confidential whistleblower process
|
||||
|
||||
## Purpose
|
||||
|
||||
It encourages and enables employees to raise serious concerns (violations of
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "OPS-REP-002"
|
||||
category: "operations/reporting"
|
||||
id: "PER.LIF.005"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
necessity: "optional"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"]
|
||||
---
|
||||
|
||||
# Run performance reviews
|
||||
|
||||
## Purpose
|
||||
|
||||
Makes sure your team has the skills and focus needed to protect what matters
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "OPS-REP-003"
|
||||
category: "operations/reporting"
|
||||
id: "PER.LIF.006"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
|
||||
---
|
||||
|
||||
# Specify security responsabilities
|
||||
|
||||
## Purpose
|
||||
|
||||
Having clear ownership improve accountability, it helps employees figure out
|
||||
@@ -1,14 +1,17 @@
|
||||
---
|
||||
id: "OPS.TRN-001"
|
||||
id: "PER.LIF.007"
|
||||
category: "operations/training"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
necessity: "optional"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC2.2"]
|
||||
---
|
||||
|
||||
# Train your employees on security
|
||||
|
||||
## Purpose
|
||||
|
||||
Your employees are the main target of cyber threats (especially phishing and
|
||||
Reference in New Issue
Block a user