@@ -1,30 +0,0 @@
|
||||
---
|
||||
id: "OPS-REP-001"
|
||||
category: "operations/reporting"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC2.2"]
|
||||
---
|
||||
|
||||
## Purpose
|
||||
|
||||
It encourages and enables employees to raise serious concerns (violations of
|
||||
your code of ethics or law or regulations) in order for them to be addressed and
|
||||
corrected while being protected from any retaliation.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Google Workspace
|
||||
|
||||
1. Set up an anonymous
|
||||
[Google form](https://html.form.guide/google-forms/make-google-form-survey-anonymous/)
|
||||
|
||||
2. Communicate the link to your employees by explaining how and why they should
|
||||
use it.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of its communication to your employees.
|
||||
@@ -1,29 +0,0 @@
|
||||
---
|
||||
id: "OPS-REP-002"
|
||||
category: "operations/reporting"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"]
|
||||
---
|
||||
|
||||
## Purpose
|
||||
|
||||
Makes sure your team has the skills and focus needed to protect what matters
|
||||
most in your business. They help spot training gaps, reinforce accountability
|
||||
and ensure everyone is aligned with your operational goals - security being one
|
||||
of them. It's all about building a culture that proactively minimizes risks
|
||||
while continuously improving.
|
||||
|
||||
## Implementation
|
||||
|
||||
Create a simple employee
|
||||
[performance evaluation process](templates/performance-review-process.md). It
|
||||
must rely on clear metrics and expectations and must be run at least once a
|
||||
year.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your performance review process.
|
||||
@@ -1,31 +0,0 @@
|
||||
---
|
||||
id: "OPS-REP-003"
|
||||
category: "operations/reporting"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
|
||||
---
|
||||
|
||||
## Purpose
|
||||
|
||||
Having clear ownership improve accountability, it helps employees figure out
|
||||
what is legit and what is not.
|
||||
|
||||
## Implementation
|
||||
|
||||
Here is the kind of document expected - it has to be done for every role with a
|
||||
potential impact on security:
|
||||
|
||||
| Role | Responsibilities |
|
||||
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices<br>• Implements and enforces security policies across all engineering teams<br>• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management<br>• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
|
||||
| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy<br>• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures<br>• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process<br>• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
|
||||
| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems<br>• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control<br>• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
|
||||
| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place<br>• Manages access for new joiners and leavers for all general software and platforms<br>• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles<br>• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your page where those responsibilities are shared.
|
||||
@@ -1,52 +0,0 @@
|
||||
### **Objective**:
|
||||
|
||||
Provide clear and constructive feedback, encourage growth and development and
|
||||
align individual goals with company objectives.
|
||||
|
||||
### **Review schedule**
|
||||
|
||||
- **Frequency**: Conduct performance reviews **semi-annually** (every 6 months).
|
||||
- **Duration**: Each review meeting should last between **30 minutes to 1
|
||||
hour**.
|
||||
- **Preparation time**: Allow managers and employees at least **one week** to
|
||||
prepare for the review.
|
||||
|
||||
### **Components**
|
||||
|
||||
- **Self-assessment:** Employees complete a self-assessment form highlighting
|
||||
their achievements, challenges and areas for improvement.
|
||||
- **Manager feedback:** Managers evaluate employee performance based on their
|
||||
responsibilities and taks, their growth, their collaboration and their
|
||||
alignment with the company value.
|
||||
- **Goal setting:** Employees and managers review progress on previously set
|
||||
goals and set 2-3 clear, measurable goals for the next period.
|
||||
|
||||
### **Process**
|
||||
|
||||
1. **Preparation**:
|
||||
|
||||
Distribute a **performance review template** (self-assessment + manager
|
||||
evaluation) one week before the review: employee and manager complete their
|
||||
sections.
|
||||
|
||||
[Performance review template](https://www.notion.so/Performance-review-template-13f1cc0bd5bc801f8b58fbc8679b4b02?pvs=21)
|
||||
|
||||
2. **Review meeting (1o1)**:
|
||||
|
||||
**Start Positive**: Begin with recognition of the employee’s contributions
|
||||
and strengths.
|
||||
|
||||
**Discuss Feedback**: Review the self-assessment and manager’s evaluation -
|
||||
for each, examples of successes or areas for improvement are expected.
|
||||
|
||||
**Collaborative Goal Setting**: Discuss growth opportunities and align new
|
||||
goals. Are training or support needed?
|
||||
|
||||
3. **Commit**:
|
||||
|
||||
Commit on the outcome of the discussion by filling in the Performance Review
|
||||
Template
|
||||
|
||||
### **Documentation**
|
||||
|
||||
Maintain a confidential records of the performance reviews.
|
||||
@@ -1,42 +0,0 @@
|
||||
---
|
||||
id: "OPS.TRN-001"
|
||||
category: "operations/training"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC2.2"]
|
||||
---
|
||||
|
||||
## Purpose
|
||||
|
||||
Your employees are the main target of cyber threats (especially phishing and
|
||||
social engineering), and education is one of the best way to reduce risk.
|
||||
Awareness of your employees will improve your company security.
|
||||
|
||||
## Implementation
|
||||
|
||||
There are a few options on the market, we will guide you through
|
||||
[Riot](https://tryriot.com/fr/) setup.
|
||||
|
||||
### Riot
|
||||
|
||||
1. **Sign up:** Go to the Riot website ([tryriot.com](https://tryriot.com/)) and
|
||||
either start a free trial or book a demo to get your account set up.
|
||||
|
||||
2. **Install on slack**: If you’re using Slack, you can install Riot directly
|
||||
from the [Slack Marketplace](https://slack.com/apps/A01GSNM2H6V-riot).
|
||||
|
||||
3. **Set up phishing simulations and security training**: After installation,
|
||||
you can begin running phishing simulations to test your team’s readiness
|
||||
against attacks. You can also automate ongoing security training programs
|
||||
that run throughout the year to keep employees aware of best practices.
|
||||
|
||||
4. **Monitor and Track Progress**: Once the setup is complete, you can track
|
||||
your team's engagement and security posture through Riot’s dashboard, which
|
||||
allows you to monitor progress and export compliance reports as needed.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your program in Riot with completion.
|
||||
Reference in New Issue
Block a user