Add securtiy responsabilities control
Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
---
|
||||
id: "OPS-REP-003"
|
||||
category: "operations/reporting"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-13"
|
||||
estimate-time: "15m"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
|
||||
---
|
||||
|
||||
## Purpose
|
||||
|
||||
Having clear ownership improve accountability, it helps employees
|
||||
figure out what is legit and what is not.
|
||||
|
||||
## Implementation
|
||||
|
||||
Here is the kind of document expected - it has to be done for every
|
||||
role with a potential impact on security:
|
||||
|
||||
| Role | Responsibilities |
|
||||
|------|-----------------|
|
||||
| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices<br>• Implements and enforces security policies across all engineering teams<br>• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management<br>• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
|
||||
| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy<br>• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures<br>• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process<br>• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
|
||||
| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems<br>• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control<br>• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
|
||||
| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place<br>• Manages access for new joiners and leavers for all general software and platforms<br>• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles<br>• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot of your page where those responsibilities are shared.
|
||||
Reference in New Issue
Block a user