diff --git a/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md b/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md new file mode 100644 index 000000000..d22a278ed --- /dev/null +++ b/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md @@ -0,0 +1,31 @@ +--- +id: "OPS-REP-003" +category: "operations/reporting" +revision-version: 1 +revision-date: "2024-01-13" +estimate-time: "15m" +frameworks: + - name: "soc2" + sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"] +--- + +## Purpose + +Having clear ownership improve accountability, it helps employees +figure out what is legit and what is not. + +## Implementation + +Here is the kind of document expected - it has to be done for every +role with a potential impact on security: + +| Role | Responsibilities | +|------|-----------------| +| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices
• Implements and enforces security policies across all engineering teams
• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management
• Coordinates the implementation of access controls, encryption protocols, and incident response procedures | +| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy
• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures
• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process
• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements | +| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems
• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control
• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements | +| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place
• Manages access for new joiners and leavers for all general software and platforms
• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles
• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data | + +## Evidence + +- Screenshot of your page where those responsibilities are shared.