Remap categories

Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-14 11:34:46 +01:00
parent 77b6a273cb
commit 15c6902c13
15 changed files with 62 additions and 24 deletions

View File

@@ -1,30 +0,0 @@
---
id: "OPS-REP-001"
category: "operations/reporting"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC2.2"]
---
## Purpose
It encourages and enables employees to raise serious concerns (violations of
your code of ethics or law or regulations) in order for them to be addressed and
corrected while being protected from any retaliation.
## Implementation
### Google Workspace
1. Set up an anonymous
[Google form](https://html.form.guide/google-forms/make-google-form-survey-anonymous/)
2. Communicate the link to your employees by explaining how and why they should
use it.
## Evidence
- Screenshot of its communication to your employees.

View File

@@ -1,29 +0,0 @@
---
id: "OPS-REP-002"
category: "operations/reporting"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "30m"
frameworks:
- name: "soc2"
sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"]
---
## Purpose
Makes sure your team has the skills and focus needed to protect what matters
most in your business. They help spot training gaps, reinforce accountability
and ensure everyone is aligned with your operational goals - security being one
of them. It's all about building a culture that proactively minimizes risks
while continuously improving.
## Implementation
Create a simple employee
[performance evaluation process](templates/performance-review-process.md). It
must rely on clear metrics and expectations and must be run at least once a
year.
## Evidence
- Screenshot of your performance review process.

View File

@@ -1,31 +0,0 @@
---
id: "OPS-REP-003"
category: "operations/reporting"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
---
## Purpose
Having clear ownership improve accountability, it helps employees figure out
what is legit and what is not.
## Implementation
Here is the kind of document expected - it has to be done for every role with a
potential impact on security:
| Role | Responsibilities |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices<br>• Implements and enforces security policies across all engineering teams<br>• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management<br>• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy<br>• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures<br>• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process<br>• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems<br>• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control<br>• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place<br>• Manages access for new joiners and leavers for all general software and platforms<br>• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles<br>• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
## Evidence
- Screenshot of your page where those responsibilities are shared.

View File

@@ -1,52 +0,0 @@
### **Objective**:
Provide clear and constructive feedback, encourage growth and development and
align individual goals with company objectives.
### **Review schedule**
- **Frequency**: Conduct performance reviews **semi-annually** (every 6 months).
- **Duration**: Each review meeting should last between **30 minutes to 1
hour**.
- **Preparation time**: Allow managers and employees at least **one week** to
prepare for the review.
### **Components**
- **Self-assessment:** Employees complete a self-assessment form highlighting
their achievements, challenges and areas for improvement.
- **Manager feedback:** Managers evaluate employee performance based on their
responsibilities and taks, their growth, their collaboration and their
alignment with the company value.
- **Goal setting:** Employees and managers review progress on previously set
goals and set 2-3 clear, measurable goals for the next period.
### **Process**
1. **Preparation**:
Distribute a **performance review template** (self-assessment + manager
evaluation) one week before the review: employee and manager complete their
sections.
[Performance review template](https://www.notion.so/Performance-review-template-13f1cc0bd5bc801f8b58fbc8679b4b02?pvs=21)
2. **Review meeting (1o1)**:
**Start Positive**: Begin with recognition of the employee’s contributions
and strengths.
**Discuss Feedback**: Review the self-assessment and manager’s evaluation -
for each, examples of successes or areas for improvement are expected.
**Collaborative Goal Setting**: Discuss growth opportunities and align new
goals. Are training or support needed?
3. **Commit**:
Commit on the outcome of the discussion by filling in the Performance Review
Template
### **Documentation**
Maintain a confidential records of the performance reviews.

View File

@@ -1,42 +0,0 @@
---
id: "OPS.TRN-001"
category: "operations/training"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "30m"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC2.2"]
---
## Purpose
Your employees are the main target of cyber threats (especially phishing and
social engineering), and education is one of the best way to reduce risk.
Awareness of your employees will improve your company security.
## Implementation
There are a few options on the market, we will guide you through
[Riot](https://tryriot.com/fr/) setup.
### Riot
1. **Sign up:** Go to the Riot website ([tryriot.com](https://tryriot.com/)) and
either start a free trial or book a demo to get your account set up.
2. **Install on slack**: If you’re using Slack, you can install Riot directly
from the [Slack Marketplace](https://slack.com/apps/A01GSNM2H6V-riot).
3. **Set up phishing simulations and security training**: After installation,
you can begin running phishing simulations to test your team’s readiness
against attacks. You can also automate ongoing security training programs
that run throughout the year to keep employees aware of best practices.
4. **Monitor and Track Progress**: Once the setup is complete, you can track
your team's engagement and security posture through Riot’s dashboard, which
allows you to monitor progress and export compliance reports as needed.
## Evidence
- Screenshot of your program in Riot with completion.