@@ -0,0 +1,30 @@
|
||||
---
|
||||
id: "PHY.FAC.001"
|
||||
category: "physical/facilities"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
necessity: "optional"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.4"]
|
||||
---
|
||||
|
||||
# Cloud datacenter physical security
|
||||
|
||||
## Purpose
|
||||
|
||||
You know how critical a data center is. You don’t want unauthorized people to
|
||||
access it.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Google Cloud Platform
|
||||
|
||||
Nothing, it is already done
|
||||
|
||||
> Evidence to provide: https://cloud.google.com/trust-center?hl=en
|
||||
|
||||
## Evidence
|
||||
|
||||
- Security document of your datacenter.
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
id: "PHY.FAC.002"
|
||||
category: "physical/facilities"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.4"]
|
||||
---
|
||||
|
||||
# Implement Physical Access Control
|
||||
|
||||
## Purpose
|
||||
|
||||
Even if you do most of your business online, you still have offices, computers
|
||||
or even printed document: you need to make sure those assets are physically
|
||||
secured (we will focus on the digital access later).
|
||||
|
||||
## Implementation
|
||||
|
||||
If you are working from a co-working space or subleasing offices, you
|
||||
don’t have much do to. Provide a link to their access policy and the
|
||||
dashboard they probably provide to manage the list of authorized
|
||||
personnel.
|
||||
|
||||
If you have your own office space, you need to provide:
|
||||
|
||||
- The security system/measure you implemented (badge, pin, etc…) - select the
|
||||
right element in the evidence section.
|
||||
- The dashboard where you track authorized personnel.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Access policy document from your co-working provider.
|
||||
- Screenshot of the dashboard with a list of authorized personnel.
|
||||
@@ -0,0 +1,29 @@
|
||||
---
|
||||
id: "PHY.FAC.003"
|
||||
category: "physical/facilities"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.4"]
|
||||
---
|
||||
|
||||
# Implement Visitor Access Policies
|
||||
|
||||
## Purpose
|
||||
|
||||
Even if you do most of your business online, you still have offices,
|
||||
computers or even printed document: you need to make sure those assets
|
||||
are physically secured (we will focus on the digital access later)
|
||||
regarding visitors.
|
||||
|
||||
## Implementation
|
||||
|
||||
Nothing, it is done! The element below will be added to your access policy.
|
||||
|
||||
## Evidence
|
||||
|
||||
Visitors must be accompanied by an employee at all times when they are on
|
||||
premises.
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
id: "PHY.FAC.004"
|
||||
category: "physical/facilities"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "4h"
|
||||
necessity: "optional"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC6.1", "CC6.6", "CC6.7"]
|
||||
---
|
||||
|
||||
# Use VPNs to Secure Access for Remote Devices
|
||||
|
||||
## Purpose
|
||||
|
||||
In short, implementing a VPN will encrypt your data and ensure a safe
|
||||
transmission between your employees devices and your internal network
|
||||
(even when using untrusted networks like a public wifi) ⇒ it offers a
|
||||
layer of security for your data.
|
||||
|
||||
## Implementation
|
||||
|
||||
> If you have doubt whether you should do it or not, ping us on
|
||||
> Discord.
|
||||
<br/>
|
||||
> If everything is on Google Suite/Notion/Slack with MFA and you don’t
|
||||
> have your own network => no needed.
|
||||
|
||||
If you think you need one, you should consider deploying one and make
|
||||
it mandatory when working remote => You can follow the [Wireguard
|
||||
installation guide there](https://www.wireguard.com/install/).
|
||||
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of VPN settings page (to show active use) or log of VPN
|
||||
connection from employees device.
|
||||
Reference in New Issue
Block a user