Add securtiy responsabilities control

Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-13 15:49:02 +01:00
parent 42f2f6e0ca
commit 7c81887d5e

View File

@@ -0,0 +1,31 @@
---
id: "OPS-REP-003"
category: "operations/reporting"
revision-version: 1
revision-date: "2024-01-13"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
---
## Purpose
Having clear ownership improve accountability, it helps employees
figure out what is legit and what is not.
## Implementation
Here is the kind of document expected - it has to be done for every
role with a potential impact on security:
| Role | Responsibilities |
|------|-----------------|
| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices<br>• Implements and enforces security policies across all engineering teams<br>• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management<br>• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy<br>• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures<br>• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process<br>• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems<br>• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control<br>• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place<br>• Manages access for new joiners and leavers for all general software and platforms<br>• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles<br>• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
## Evidence
- Screenshot of your page where those responsibilities are shared.