From 42f2f6e0ca73150ea33749954ece9c45094bcc49 Mon Sep 17 00:00:00 2001 From: gearnode Date: Mon, 13 Jan 2025 15:42:49 +0100 Subject: [PATCH] Add performance review control Signed-off-by: gearnode --- .../OPS.REP.002_performance_reviews.md | 29 +++++++++++ .../templates/performance-review-process.md | 52 +++++++++++++++++++ 2 files changed, 81 insertions(+) create mode 100644 controls/operations/reporting/OPS.REP.002_performance_reviews.md create mode 100644 controls/operations/reporting/templates/performance-review-process.md diff --git a/controls/operations/reporting/OPS.REP.002_performance_reviews.md b/controls/operations/reporting/OPS.REP.002_performance_reviews.md new file mode 100644 index 000000000..84d389185 --- /dev/null +++ b/controls/operations/reporting/OPS.REP.002_performance_reviews.md @@ -0,0 +1,29 @@ +--- +id: "OPS-REP-002" +category: "operations/reporting" +revision-version: 1 +revision-date: "2024-01-13" +estimate-time: "30m" +frameworks: + - name: "soc2" + sections: ["CC1.3", "CC1.4", "CC1.5", "CC4.2", "CC5.3"] +--- + +## Purpose + +Makes sure your team has the skills and focus needed to protect what matters +most in your business. They help spot training gaps, reinforce accountability +and ensure everyone is aligned with your operational goals - security being one +of them. It's all about building a culture that proactively minimizes risks +while continuously improving. + +## Implementation + +Create a simple employee +[performance evaluation process](templates/performance-review-process.md). It +must rely on clear metrics and expectations and must be run at least once a +year. + +## Evidence + +- Screenshot of your performance review process. diff --git a/controls/operations/reporting/templates/performance-review-process.md b/controls/operations/reporting/templates/performance-review-process.md new file mode 100644 index 000000000..1d4b30850 --- /dev/null +++ b/controls/operations/reporting/templates/performance-review-process.md @@ -0,0 +1,52 @@ +### **Objective**: + +Provide clear and constructive feedback, encourage growth and development and +align individual goals with company objectives. + +### **Review schedule** + +- **Frequency**: Conduct performance reviews **semi-annually** (every 6 months). +- **Duration**: Each review meeting should last between **30 minutes to 1 + hour**. +- **Preparation time**: Allow managers and employees at least **one week** to + prepare for the review. + +### **Components** + +- **Self-assessment:** Employees complete a self-assessment form highlighting + their achievements, challenges and areas for improvement. +- **Manager feedback:** Managers evaluate employee performance based on their + responsibilities and taks, their growth, their collaboration and their + alignment with the company value. +- **Goal setting:** Employees and managers review progress on previously set + goals and set 2-3 clear, measurable goals for the next period. + +### **Process** + +1. **Preparation**: + + Distribute a **performance review template** (self-assessment + manager + evaluation) one week before the review: employee and manager complete their + sections. + + [Performance review template](https://www.notion.so/Performance-review-template-13f1cc0bd5bc801f8b58fbc8679b4b02?pvs=21) + +2. **Review meeting (1o1)**: + + **Start Positive**: Begin with recognition of the employee’s contributions + and strengths. + + **Discuss Feedback**: Review the self-assessment and manager’s evaluation - + for each, examples of successes or areas for improvement are expected. + + **Collaborative Goal Setting**: Discuss growth opportunities and align new + goals. Are training or support needed? + +3. **Commit**: + + Commit on the outcome of the discussion by filling in the Performance Review + Template + +### **Documentation** + +Maintain a confidential records of the performance reviews.