@@ -0,0 +1,46 @@
|
||||
---
|
||||
id: "PER.COM.001"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.8"]
|
||||
---
|
||||
|
||||
# Configure SPF for Email Authentication
|
||||
|
||||
## Purpose
|
||||
|
||||
SPF (Sender Policy Framework) prevents email spoofing by defining which mail
|
||||
servers are authorized to send emails on behalf of your domain. It helps
|
||||
receiving mail servers verify that incoming email from a domain comes from a
|
||||
host authorized by that domain's administrators.
|
||||
|
||||
## Implementation
|
||||
|
||||
1. Identify all legitimate email sources:
|
||||
- Your mail servers
|
||||
- Third-party services (e.g., Google Workspace)
|
||||
- Marketing platforms
|
||||
- Any other authorized email senders
|
||||
2. Create SPF record
|
||||
```
|
||||
v=spf1 include:_spf.google.com ~all
|
||||
```
|
||||
Where:
|
||||
- `v=spf1`: Version of SPF
|
||||
- `include:_spf.google.com`: Include Google's mail servers
|
||||
- `~all`: Soft fail for others (can be changed to -all for hard fail)
|
||||
3. Add record to DNS:
|
||||
- Create TXT record at domain root
|
||||
- Publish SPF record in DNS
|
||||
- Wait for DNS propagation
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of published SPF DNS record
|
||||
- Email header samples showing SPF pass
|
||||
- Documentation of authorized senders
|
||||
37
controls/personnel/comms/PER.COM.002.dkim_implementation.md
Normal file
37
controls/personnel/comms/PER.COM.002.dkim_implementation.md
Normal file
@@ -0,0 +1,37 @@
|
||||
---
|
||||
id: "PER.COM.002"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.8"]
|
||||
---
|
||||
|
||||
# Configure DKIM for Email Authentication
|
||||
|
||||
## Purpose
|
||||
|
||||
DKIM (DomainKeys Identified Mail) helps prevent email spoofing by adding a
|
||||
digital signature to outgoing messages, allowing receiving mail systems to
|
||||
verify that emails genuinely came from your domain and weren't modified in
|
||||
transit.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Google Workspace
|
||||
|
||||
1. Go to [Google Admin console](admin.google.com).
|
||||
2. Navigate to Apps > Google Workspace > Gmail > Authenticate Email.
|
||||
3. Select your domain and click "Generate new record".
|
||||
4. Copy the DKIM TXT record provided by Google.
|
||||
5. Add this TXT record to your DNS.
|
||||
6. After DNS propagation, return to Admin console and click "Start
|
||||
authentication".
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of published DKIM DNS record
|
||||
- Sample email headers showing DKIM pass
|
||||
@@ -0,0 +1,48 @@
|
||||
---
|
||||
id: "PER.COM.003"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
related:
|
||||
- id: "PER.COM.001"
|
||||
required: true
|
||||
- id: "PER.COM.002"
|
||||
required: true
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.8"]
|
||||
---
|
||||
|
||||
# Configure DMARC for Email Authentication
|
||||
|
||||
## Purpose
|
||||
|
||||
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a
|
||||
policy framework that builds upon SPF and DKIM. It tells receiving servers what
|
||||
to do when emails fail SPF or DKIM checks, and provides reporting on
|
||||
authentication results.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Google Workspace
|
||||
|
||||
1. Create a Google Group named `dmarc-report@example.com` which is assecible
|
||||
from external users.
|
||||
2. Create DMARC record in monitoring mode:
|
||||
```
|
||||
Record: _dmarc.example.com
|
||||
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
|
||||
```
|
||||
Where:
|
||||
- `v=DMARC1`: Protocol version
|
||||
- `p=none`: Policy for failed checks
|
||||
- `rua=`: Address for aggregate reports
|
||||
3. Check the reports sent to the rua email address to ensure proper
|
||||
authentication of emails.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of DMARC DNS record
|
||||
- Sample aggregate reports
|
||||
@@ -0,0 +1,42 @@
|
||||
---
|
||||
id: "PER.COM.004"
|
||||
category: "personnel/comms"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.8", "CC7.2"]
|
||||
---
|
||||
|
||||
# Configure Email Security Filters
|
||||
|
||||
## Purpose
|
||||
|
||||
Implement email filtering and warning systems to reduce phishing risks and
|
||||
protect employees from malicious emails. This reduces mental load on employees
|
||||
and decreases company risk exposure through email-based attacks.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Google Workspace
|
||||
|
||||
1. Access [Google Admin Console](https://admin.google.com).
|
||||
2. Navigate to Settings
|
||||
```
|
||||
Apps → Google Workspace → Gmail
|
||||
```
|
||||
3. Configure "Safety" settings:
|
||||
- Attachments Protection
|
||||
- Scan for anomalous attachment types
|
||||
- Block attachments with scripts
|
||||
- Block encrypted attachments from untrusted senders
|
||||
- Links and External Images:
|
||||
- Enable scanning of linked images
|
||||
- Identify shortened URLs
|
||||
- Display warning prompts for untrusted domains
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of email security settings in Google Admin Console.
|
||||
47
controls/personnel/lifecycle/PER.LIF.001_onboarding.md
Normal file
47
controls/personnel/lifecycle/PER.LIF.001_onboarding.md
Normal file
@@ -0,0 +1,47 @@
|
||||
---
|
||||
id: "PER.LIF.001"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-10"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC5.3"]
|
||||
---
|
||||
|
||||
# Integrate security checklist in your onboarding process
|
||||
|
||||
## Purpose
|
||||
|
||||
It is the perfect timing to ensure that every employees has:
|
||||
|
||||
- accepted and signed all documents
|
||||
- the access needed to perform his/her tasks
|
||||
- started his/her security training
|
||||
|
||||
## Implementation
|
||||
|
||||
In theory, you already have an onboarding plan for your new employees (if not,
|
||||
[Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for
|
||||
your admin running the onboarding (if not,
|
||||
[Onboarding admin checklist](templates/onboarding-admin-checklist.md)).
|
||||
|
||||
On your employee to-do, be sure to include:
|
||||
|
||||
- Set-up of 2FA
|
||||
- Set-up of password manager
|
||||
- Read & acknowledge all policies (it can be part of the contract)
|
||||
- Complete the security training
|
||||
|
||||
On your admin to-do, be sure to include:
|
||||
|
||||
- contract is signed before granting access
|
||||
- apply “least privilege principle” for access (the matrix you defined)
|
||||
- Force the set-up of 2FA and password manager
|
||||
- Initiate the security training
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshots of a completed onboarding checklists.
|
||||
- Screenshots of a completed admin checklist for new joiner.
|
||||
39
controls/personnel/lifecycle/PER.LIF.002_offboarding.md
Normal file
39
controls/personnel/lifecycle/PER.LIF.002_offboarding.md
Normal file
@@ -0,0 +1,39 @@
|
||||
---
|
||||
id: "PER.LIF.002"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-10"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC5.3", "CC6.2", "CC6.5"]
|
||||
---
|
||||
|
||||
# Properly off-board your employees
|
||||
|
||||
## Purpose
|
||||
|
||||
Yes, people will leave your company (either by your decision or theirs). And you
|
||||
want to be prepare! If an early employee leaves and you forgot to change the
|
||||
ownership on his/her document, you might lose the documents.
|
||||
|
||||
Also, you want to be sure people can’t access the company data or systems once
|
||||
they left!
|
||||
|
||||
## Implementation
|
||||
|
||||
1. Integrate the following elements in your offboarding checklist:
|
||||
|
||||
- Return of company assets (laptop etc.)
|
||||
- Transfer ownership of documents
|
||||
- Revoke all access to systems
|
||||
|
||||
(if you don't have an offboarding checklist →
|
||||
[Offboarding admin checklist](templates/offboarding-admin-checklist.md))
|
||||
|
||||
2. Upload a screenshot of your checklist that contains those bullet points below
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of a completed admin checklist for offboarding
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
id: "PER.LIF.003"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-10"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC5.3"]
|
||||
---
|
||||
|
||||
# Know your recruits
|
||||
|
||||
## Purpose
|
||||
|
||||
When recruiting someone, you want to be sure of who you are hiring: by
|
||||
performing reference checks (it can also be background checks), you add an
|
||||
additional layer of certainty on the candidate by looking for potential red
|
||||
flags in the candidate’s past (history of unethical behavior, harassment, fraud,
|
||||
etc..).
|
||||
|
||||
## Implementation
|
||||
|
||||
Recruitment is key, especially early stage, so you are probably already doing it
|
||||
right, it is only about documenting it.
|
||||
|
||||
⇒ Define the recruitment process you follow when bringing on a new member (if
|
||||
you don’t have one formalized, here is a structure:
|
||||
[Recruitment process](templates/recruitment-process.md)).
|
||||
|
||||
## Evidence
|
||||
|
||||
- Reference check template
|
||||
- Completed check records (redacted)
|
||||
- Process documentation
|
||||
- Verification records
|
||||
@@ -0,0 +1,33 @@
|
||||
---
|
||||
id: "PER.LIF.004"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC2.2"]
|
||||
---
|
||||
|
||||
# Implement confidential whistleblower process
|
||||
|
||||
## Purpose
|
||||
|
||||
It encourages and enables employees to raise serious concerns (violations of
|
||||
your code of ethics or law or regulations) in order for them to be addressed and
|
||||
corrected while being protected from any retaliation.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Google Workspace
|
||||
|
||||
1. Set up an anonymous
|
||||
[Google form](https://html.form.guide/google-forms/make-google-form-survey-anonymous/)
|
||||
|
||||
2. Communicate the link to your employees by explaining how and why they should
|
||||
use it.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of its communication to your employees.
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
id: "PER.LIF.005"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
necessity: "optional"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"]
|
||||
---
|
||||
|
||||
# Run performance reviews
|
||||
|
||||
## Purpose
|
||||
|
||||
Makes sure your team has the skills and focus needed to protect what matters
|
||||
most in your business. They help spot training gaps, reinforce accountability
|
||||
and ensure everyone is aligned with your operational goals - security being one
|
||||
of them. It's all about building a culture that proactively minimizes risks
|
||||
while continuously improving.
|
||||
|
||||
## Implementation
|
||||
|
||||
Create a simple employee
|
||||
[performance evaluation process](templates/performance-review-process.md). It
|
||||
must rely on clear metrics and expectations and must be run at least once a
|
||||
year.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your performance review process.
|
||||
@@ -0,0 +1,34 @@
|
||||
---
|
||||
id: "PER.LIF.006"
|
||||
category: "personnel/lifecycle"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
|
||||
---
|
||||
|
||||
# Specify security responsabilities
|
||||
|
||||
## Purpose
|
||||
|
||||
Having clear ownership improve accountability, it helps employees figure out
|
||||
what is legit and what is not.
|
||||
|
||||
## Implementation
|
||||
|
||||
Here is the kind of document expected - it has to be done for every role with a
|
||||
potential impact on security:
|
||||
|
||||
| Role | Responsibilities |
|
||||
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices<br>• Implements and enforces security policies across all engineering teams<br>• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management<br>• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
|
||||
| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy<br>• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures<br>• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process<br>• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
|
||||
| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems<br>• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control<br>• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
|
||||
| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place<br>• Manages access for new joiners and leavers for all general software and platforms<br>• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles<br>• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your page where those responsibilities are shared.
|
||||
@@ -0,0 +1,45 @@
|
||||
---
|
||||
id: "PER.LIF.007"
|
||||
category: "operations/training"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
necessity: "optional"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.4", "CC2.2"]
|
||||
---
|
||||
|
||||
# Train your employees on security
|
||||
|
||||
## Purpose
|
||||
|
||||
Your employees are the main target of cyber threats (especially phishing and
|
||||
social engineering), and education is one of the best way to reduce risk.
|
||||
Awareness of your employees will improve your company security.
|
||||
|
||||
## Implementation
|
||||
|
||||
There are a few options on the market, we will guide you through
|
||||
[Riot](https://tryriot.com/fr/) setup.
|
||||
|
||||
### Riot
|
||||
|
||||
1. **Sign up:** Go to the Riot website ([tryriot.com](https://tryriot.com/)) and
|
||||
either start a free trial or book a demo to get your account set up.
|
||||
|
||||
2. **Install on slack**: If you’re using Slack, you can install Riot directly
|
||||
from the [Slack Marketplace](https://slack.com/apps/A01GSNM2H6V-riot).
|
||||
|
||||
3. **Set up phishing simulations and security training**: After installation,
|
||||
you can begin running phishing simulations to test your team’s readiness
|
||||
against attacks. You can also automate ongoing security training programs
|
||||
that run throughout the year to keep employees aware of best practices.
|
||||
|
||||
4. **Monitor and Track Progress**: Once the setup is complete, you can track
|
||||
your team's engagement and security posture through Riot’s dashboard, which
|
||||
allows you to monitor progress and export compliance reports as needed.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your program in Riot with completion.
|
||||
@@ -0,0 +1,9 @@
|
||||
- [ ] 💰 Make sure we closed the contract on Payfit
|
||||
- [ ] 💻 Get back and Reset laptop
|
||||
- [ ] 🔁 Transfert the docs ownership in Google
|
||||
- [ ] 📧 Suppress the Google account
|
||||
- [ ] 🖋 Disconnect manually Notion
|
||||
- [ ] 🛠 Disconnect Slack
|
||||
- [ ] 🔐 Delete from 1 Password (not suspended, billed)
|
||||
- [ ] 🗄 Disconnect manually Github
|
||||
- [ ] 🧐 Double check with the manager for important tool
|
||||
@@ -0,0 +1,48 @@
|
||||
# Onboarding for new joiner
|
||||
|
||||
## 💜 Welcome! We're so glad to have you 😃
|
||||
|
||||
This first week will be about discovery: discovering the team, the way we work,
|
||||
and what we do.
|
||||
|
||||
> 💡Here is a checklist to help you settle down. Feel free to navigate notion &
|
||||
> slack, or to ask questions to anyone. Our role is to make your first days as
|
||||
> easy as possible.
|
||||
|
||||
## 🆕 Setting you up
|
||||
|
||||
- [ ] Log in to your Google Account (you must have received an email) and set up
|
||||
a new password
|
||||
- [ ] Download Google Authenticator app for 2-factor auth
|
||||
- [ ] Set-up the 2-factor auth: it is mandatory
|
||||
- [ ] Log in to 1password
|
||||
- [ ] Log in to Slack with your google account
|
||||
- [ ] Log in to Notion with your google account
|
||||
- [ ] Complete Albert security training on Slack
|
||||
|
||||
## 👷 Your Onboarding Project
|
||||
|
||||
> You’re now ready to present yourself to the team!
|
||||
|
||||
- [ ] Share a few things about you in #all_people in Slack: who are you, where
|
||||
do you come from, what was your journey until now, whatever fun fact you’d
|
||||
like to share with us, … you can draw some inspiration by looking at the
|
||||
previous ones 🙂
|
||||
- [ ] Read our Code of Conduct
|
||||
- [ ] Put a picture of yourself on Slack
|
||||
|
||||
## 👥 Users
|
||||
|
||||
If you want to know more about our users, go check XXXX
|
||||
|
||||
## 🚀 To go further
|
||||
|
||||
**Meet the team 🤝**
|
||||
|
||||
- [ ] Join the #coffee-chats channel for random coffee breaks
|
||||
- [ ] Schedule a chat with every member of your team to get to know them 💜
|
||||
|
||||
**Understand what we do ❓**
|
||||
|
||||
- [ ] Take some time to navigate on our Notion pages 🧭
|
||||
- [ ] Get your access to our product to play with it - follow the guide XXXX
|
||||
@@ -0,0 +1,52 @@
|
||||
### **Objective**:
|
||||
|
||||
Provide clear and constructive feedback, encourage growth and development and
|
||||
align individual goals with company objectives.
|
||||
|
||||
### **Review schedule**
|
||||
|
||||
- **Frequency**: Conduct performance reviews **semi-annually** (every 6 months).
|
||||
- **Duration**: Each review meeting should last between **30 minutes to 1
|
||||
hour**.
|
||||
- **Preparation time**: Allow managers and employees at least **one week** to
|
||||
prepare for the review.
|
||||
|
||||
### **Components**
|
||||
|
||||
- **Self-assessment:** Employees complete a self-assessment form highlighting
|
||||
their achievements, challenges and areas for improvement.
|
||||
- **Manager feedback:** Managers evaluate employee performance based on their
|
||||
responsibilities and taks, their growth, their collaboration and their
|
||||
alignment with the company value.
|
||||
- **Goal setting:** Employees and managers review progress on previously set
|
||||
goals and set 2-3 clear, measurable goals for the next period.
|
||||
|
||||
### **Process**
|
||||
|
||||
1. **Preparation**:
|
||||
|
||||
Distribute a **performance review template** (self-assessment + manager
|
||||
evaluation) one week before the review: employee and manager complete their
|
||||
sections.
|
||||
|
||||
[Performance review template](https://www.notion.so/Performance-review-template-13f1cc0bd5bc801f8b58fbc8679b4b02?pvs=21)
|
||||
|
||||
2. **Review meeting (1o1)**:
|
||||
|
||||
**Start Positive**: Begin with recognition of the employee’s contributions
|
||||
and strengths.
|
||||
|
||||
**Discuss Feedback**: Review the self-assessment and manager’s evaluation -
|
||||
for each, examples of successes or areas for improvement are expected.
|
||||
|
||||
**Collaborative Goal Setting**: Discuss growth opportunities and align new
|
||||
goals. Are training or support needed?
|
||||
|
||||
3. **Commit**:
|
||||
|
||||
Commit on the outcome of the discussion by filling in the Performance Review
|
||||
Template
|
||||
|
||||
### **Documentation**
|
||||
|
||||
Maintain a confidential records of the performance reviews.
|
||||
@@ -0,0 +1,10 @@
|
||||
1. Initial screen (with talent partner) - 30min
|
||||
2. Technical interview (with hiring manager) - 30min/1h
|
||||
3. Home assignment - 3/4h
|
||||
4. Assignment review (with hiring manager and one team member) - 1h
|
||||
5. Check-in call (with talent partner) -15min
|
||||
6. Final interviews: culture fit and deep dive (5 team members and a founder) -
|
||||
2x30min + 1h
|
||||
7. Reference checks - variable, based on position
|
||||
8. Offer call (with talent partner) - 30min
|
||||
9. Hire
|
||||
Reference in New Issue
Block a user