Remap categories

Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-14 11:34:46 +01:00
parent 77b6a273cb
commit 15c6902c13
15 changed files with 62 additions and 24 deletions

View File

@@ -0,0 +1,46 @@
---
id: "PER.COM.001"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC6.1", "CC6.8"]
---
# Configure SPF for Email Authentication
## Purpose
SPF (Sender Policy Framework) prevents email spoofing by defining which mail
servers are authorized to send emails on behalf of your domain. It helps
receiving mail servers verify that incoming email from a domain comes from a
host authorized by that domain's administrators.
## Implementation
1. Identify all legitimate email sources:
- Your mail servers
- Third-party services (e.g., Google Workspace)
- Marketing platforms
- Any other authorized email senders
2. Create SPF record
```
v=spf1 include:_spf.google.com ~all
```
Where:
- `v=spf1`: Version of SPF
- `include:_spf.google.com`: Include Google's mail servers
- `~all`: Soft fail for others (can be changed to -all for hard fail)
3. Add record to DNS:
- Create TXT record at domain root
- Publish SPF record in DNS
- Wait for DNS propagation
## Evidence
- Screenshot of published SPF DNS record
- Email header samples showing SPF pass
- Documentation of authorized senders

View File

@@ -0,0 +1,37 @@
---
id: "PER.COM.002"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC6.1", "CC6.8"]
---
# Configure DKIM for Email Authentication
## Purpose
DKIM (DomainKeys Identified Mail) helps prevent email spoofing by adding a
digital signature to outgoing messages, allowing receiving mail systems to
verify that emails genuinely came from your domain and weren't modified in
transit.
## Implementation
### Google Workspace
1. Go to [Google Admin console](admin.google.com).
2. Navigate to Apps > Google Workspace > Gmail > Authenticate Email.
3. Select your domain and click "Generate new record".
4. Copy the DKIM TXT record provided by Google.
5. Add this TXT record to your DNS.
6. After DNS propagation, return to Admin console and click "Start
authentication".
## Evidence
- Screenshot of published DKIM DNS record
- Sample email headers showing DKIM pass

View File

@@ -0,0 +1,48 @@
---
id: "PER.COM.003"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "30m"
necessity: "mandatory"
related:
- id: "PER.COM.001"
required: true
- id: "PER.COM.002"
required: true
frameworks:
- name: "soc2"
sections: ["CC6.1", "CC6.8"]
---
# Configure DMARC for Email Authentication
## Purpose
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a
policy framework that builds upon SPF and DKIM. It tells receiving servers what
to do when emails fail SPF or DKIM checks, and provides reporting on
authentication results.
## Implementation
### Google Workspace
1. Create a Google Group named `dmarc-report@example.com` which is assecible
from external users.
2. Create DMARC record in monitoring mode:
```
Record: _dmarc.example.com
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
```
Where:
- `v=DMARC1`: Protocol version
- `p=none`: Policy for failed checks
- `rua=`: Address for aggregate reports
3. Check the reports sent to the rua email address to ensure proper
authentication of emails.
## Evidence
- Screenshot of DMARC DNS record
- Sample aggregate reports

View File

@@ -0,0 +1,42 @@
---
id: "PER.COM.004"
category: "personnel/comms"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC6.8", "CC7.2"]
---
# Configure Email Security Filters
## Purpose
Implement email filtering and warning systems to reduce phishing risks and
protect employees from malicious emails. This reduces mental load on employees
and decreases company risk exposure through email-based attacks.
## Implementation
### Google Workspace
1. Access [Google Admin Console](https://admin.google.com).
2. Navigate to Settings
```
Apps → Google Workspace → Gmail
```
3. Configure "Safety" settings:
- Attachments Protection
- Scan for anomalous attachment types
- Block attachments with scripts
- Block encrypted attachments from untrusted senders
- Links and External Images:
- Enable scanning of linked images
- Identify shortened URLs
- Display warning prompts for untrusted domains
## Evidence
- Screenshot of email security settings in Google Admin Console.

View File

@@ -0,0 +1,47 @@
---
id: "PER.LIF.001"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.3"]
---
# Integrate security checklist in your onboarding process
## Purpose
It is the perfect timing to ensure that every employees has:
- accepted and signed all documents
- the access needed to perform his/her tasks
- started his/her security training
## Implementation
In theory, you already have an onboarding plan for your new employees (if not,
[Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for
your admin running the onboarding (if not,
[Onboarding admin checklist](templates/onboarding-admin-checklist.md)).
On your employee to-do, be sure to include:
- Set-up of 2FA
- Set-up of password manager
- Read & acknowledge all policies (it can be part of the contract)
- Complete the security training
On your admin to-do, be sure to include:
- contract is signed before granting access
- apply “least privilege principle” for access (the matrix you defined)
- Force the set-up of 2FA and password manager
- Initiate the security training
## Evidence
- Screenshots of a completed onboarding checklists.
- Screenshots of a completed admin checklist for new joiner.

View File

@@ -0,0 +1,39 @@
---
id: "PER.LIF.002"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC5.3", "CC6.2", "CC6.5"]
---
# Properly off-board your employees
## Purpose
Yes, people will leave your company (either by your decision or theirs). And you
want to be prepare! If an early employee leaves and you forgot to change the
ownership on his/her document, you might lose the documents.
Also, you want to be sure people can’t access the company data or systems once
they left!
## Implementation
1. Integrate the following elements in your offboarding checklist:
- Return of company assets (laptop etc.)
- Transfer ownership of documents
- Revoke all access to systems
(if you don't have an offboarding checklist →
[Offboarding admin checklist](templates/offboarding-admin-checklist.md))
2. Upload a screenshot of your checklist that contains those bullet points below
## Evidence
- Screenshot of a completed admin checklist for offboarding

View File

@@ -0,0 +1,37 @@
---
id: "PER.LIF.003"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.3"]
---
# Know your recruits
## Purpose
When recruiting someone, you want to be sure of who you are hiring: by
performing reference checks (it can also be background checks), you add an
additional layer of certainty on the candidate by looking for potential red
flags in the candidate’s past (history of unethical behavior, harassment, fraud,
etc..).
## Implementation
Recruitment is key, especially early stage, so you are probably already doing it
right, it is only about documenting it.
⇒ Define the recruitment process you follow when bringing on a new member (if
you don’t have one formalized, here is a structure:
[Recruitment process](templates/recruitment-process.md)).
## Evidence
- Reference check template
- Completed check records (redacted)
- Process documentation
- Verification records

View File

@@ -0,0 +1,33 @@
---
id: "PER.LIF.004"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC2.2"]
---
# Implement confidential whistleblower process
## Purpose
It encourages and enables employees to raise serious concerns (violations of
your code of ethics or law or regulations) in order for them to be addressed and
corrected while being protected from any retaliation.
## Implementation
### Google Workspace
1. Set up an anonymous
[Google form](https://html.form.guide/google-forms/make-google-form-survey-anonymous/)
2. Communicate the link to your employees by explaining how and why they should
use it.
## Evidence
- Screenshot of its communication to your employees.

View File

@@ -0,0 +1,32 @@
---
id: "PER.LIF.005"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "30m"
necessity: "optional"
frameworks:
- name: "soc2"
sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"]
---
# Run performance reviews
## Purpose
Makes sure your team has the skills and focus needed to protect what matters
most in your business. They help spot training gaps, reinforce accountability
and ensure everyone is aligned with your operational goals - security being one
of them. It's all about building a culture that proactively minimizes risks
while continuously improving.
## Implementation
Create a simple employee
[performance evaluation process](templates/performance-review-process.md). It
must rely on clear metrics and expectations and must be run at least once a
year.
## Evidence
- Screenshot of your performance review process.

View File

@@ -0,0 +1,34 @@
---
id: "PER.LIF.006"
category: "personnel/lifecycle"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
necessity: "mandatory"
frameworks:
- name: "soc2"
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
---
# Specify security responsabilities
## Purpose
Having clear ownership improve accountability, it helps employees figure out
what is legit and what is not.
## Implementation
Here is the kind of document expected - it has to be done for every role with a
potential impact on security:
| Role | Responsibilities |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices<br>• Implements and enforces security policies across all engineering teams<br>• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management<br>• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy<br>• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures<br>• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process<br>• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems<br>• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control<br>• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place<br>• Manages access for new joiners and leavers for all general software and platforms<br>• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles<br>• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
## Evidence
- Screenshot of your page where those responsibilities are shared.

View File

@@ -0,0 +1,45 @@
---
id: "PER.LIF.007"
category: "operations/training"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "30m"
necessity: "optional"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC2.2"]
---
# Train your employees on security
## Purpose
Your employees are the main target of cyber threats (especially phishing and
social engineering), and education is one of the best way to reduce risk.
Awareness of your employees will improve your company security.
## Implementation
There are a few options on the market, we will guide you through
[Riot](https://tryriot.com/fr/) setup.
### Riot
1. **Sign up:** Go to the Riot website ([tryriot.com](https://tryriot.com/)) and
either start a free trial or book a demo to get your account set up.
2. **Install on slack**: If you’re using Slack, you can install Riot directly
from the [Slack Marketplace](https://slack.com/apps/A01GSNM2H6V-riot).
3. **Set up phishing simulations and security training**: After installation,
you can begin running phishing simulations to test your team’s readiness
against attacks. You can also automate ongoing security training programs
that run throughout the year to keep employees aware of best practices.
4. **Monitor and Track Progress**: Once the setup is complete, you can track
your team's engagement and security posture through Riot’s dashboard, which
allows you to monitor progress and export compliance reports as needed.
## Evidence
- Screenshot of your program in Riot with completion.

View File

@@ -0,0 +1,9 @@
- [ ] 💰 Make sure we closed the contract on Payfit
- [ ] 💻 Get back and Reset laptop
- [ ] 🔁 Transfert the docs ownership in Google
- [ ] 📧 Suppress the Google account
- [ ] 🖋 Disconnect manually Notion
- [ ] 🛠 Disconnect Slack
- [ ] 🔐 Delete from 1 Password (not suspended, billed)
- [ ] 🗄 Disconnect manually Github
- [ ] 🧐 Double check with the manager for important tool

View File

@@ -0,0 +1,48 @@
# Onboarding for new joiner
## 💜 Welcome! We're so glad to have you 😃
This first week will be about discovery: discovering the team, the way we work,
and what we do.
> 💡Here is a checklist to help you settle down. Feel free to navigate notion &
> slack, or to ask questions to anyone. Our role is to make your first days as
> easy as possible.
## 🆕 Setting you up
- [ ] Log in to your Google Account (you must have received an email) and set up
a new password
- [ ] Download Google Authenticator app for 2-factor auth
- [ ] Set-up the 2-factor auth: it is mandatory
- [ ] Log in to 1password
- [ ] Log in to Slack with your google account
- [ ] Log in to Notion with your google account
- [ ] Complete Albert security training on Slack
## 👷 Your Onboarding Project
> You’re now ready to present yourself to the team!
- [ ] Share a few things about you in #all_people in Slack: who are you, where
do you come from, what was your journey until now, whatever fun fact you’d
like to share with us, … you can draw some inspiration by looking at the
previous ones 🙂
- [ ] Read our Code of Conduct
- [ ] Put a picture of yourself on Slack
## 👥 Users
If you want to know more about our users, go check XXXX
## 🚀 To go further
**Meet the team 🤝**
- [ ] Join the #coffee-chats channel for random coffee breaks
- [ ] Schedule a chat with every member of your team to get to know them 💜
**Understand what we do ❓**
- [ ] Take some time to navigate on our Notion pages 🧭
- [ ] Get your access to our product to play with it - follow the guide XXXX

View File

@@ -0,0 +1,52 @@
### **Objective**:
Provide clear and constructive feedback, encourage growth and development and
align individual goals with company objectives.
### **Review schedule**
- **Frequency**: Conduct performance reviews **semi-annually** (every 6 months).
- **Duration**: Each review meeting should last between **30 minutes to 1
hour**.
- **Preparation time**: Allow managers and employees at least **one week** to
prepare for the review.
### **Components**
- **Self-assessment:** Employees complete a self-assessment form highlighting
their achievements, challenges and areas for improvement.
- **Manager feedback:** Managers evaluate employee performance based on their
responsibilities and taks, their growth, their collaboration and their
alignment with the company value.
- **Goal setting:** Employees and managers review progress on previously set
goals and set 2-3 clear, measurable goals for the next period.
### **Process**
1. **Preparation**:
Distribute a **performance review template** (self-assessment + manager
evaluation) one week before the review: employee and manager complete their
sections.
[Performance review template](https://www.notion.so/Performance-review-template-13f1cc0bd5bc801f8b58fbc8679b4b02?pvs=21)
2. **Review meeting (1o1)**:
**Start Positive**: Begin with recognition of the employee’s contributions
and strengths.
**Discuss Feedback**: Review the self-assessment and manager’s evaluation -
for each, examples of successes or areas for improvement are expected.
**Collaborative Goal Setting**: Discuss growth opportunities and align new
goals. Are training or support needed?
3. **Commit**:
Commit on the outcome of the discussion by filling in the Performance Review
Template
### **Documentation**
Maintain a confidential records of the performance reviews.

View File

@@ -0,0 +1,10 @@
1. Initial screen (with talent partner) - 30min
2. Technical interview (with hiring manager) - 30min/1h
3. Home assignment - 3/4h
4. Assignment review (with hiring manager and one team member) - 1h
5. Check-in call (with talent partner) -15min
6. Final interviews: culture fit and deep dive (5 team members and a founder) -
2x30min + 1h
7. Reference checks - variable, based on position
8. Offer call (with talent partner) - 30min
9. Hire