From cbf060bf3beb6d1cc43c6b13a7f0f1dfe302c56c Mon Sep 17 00:00:00 2001 From: gearnode Date: Fri, 10 Jan 2025 16:18:10 +0100 Subject: [PATCH] Run fmt Signed-off-by: Bryan Frimin --- .../ACC.IDM.001_onboarding.md | 12 +++-- .../ACC.IDM.002_offboarding.md | 19 ++++---- ...DM.003_pre-employment-screening-process.md | 16 +++---- .../data/offboarding-admin-checklist.md | 18 ++++---- .../data/onboarding-for-new-joiner.md | 46 +++++++++---------- .../data/recruitment-process.md | 3 +- 6 files changed, 58 insertions(+), 56 deletions(-) diff --git a/controls/access/identity-management/ACC.IDM.001_onboarding.md b/controls/access/identity-management/ACC.IDM.001_onboarding.md index f154b190c..a98239386 100644 --- a/controls/access/identity-management/ACC.IDM.001_onboarding.md +++ b/controls/access/identity-management/ACC.IDM.001_onboarding.md @@ -12,25 +12,27 @@ frameworks: ## Purpose It is the perfect timing to ensure that every employees has: + - accepted and signed all documents - the access needed to perform his/her tasks - started his/her security training ## Implementation -In theory, you already have an onboarding plan for your new employees -(if not, Onboarding for new -joiner](data/onboarding-for-new-joiner.md)) and a to-do for your admin -running the onboarding (if not, [Onboarding admin -checklist](data/onboarding-admin-checklist.md)). +In theory, you already have an onboarding plan for your new employees (if not, +Onboarding for new joiner](data/onboarding-for-new-joiner.md)) and a to-do for +your admin running the onboarding (if not, +[Onboarding admin checklist](data/onboarding-admin-checklist.md)). On your employee to-do, be sure to include: + - Set-up of 2FA - Set-up of password manager - Read & acknowledge all policies (it can be part of the contract) - Complete the security training On your admin to-do, be sure to include: + - contract is signed before granting access - apply “least privilege principle” for access (the matrix you defined) - Force the set-up of 2FA and password manager diff --git a/controls/access/identity-management/ACC.IDM.002_offboarding.md b/controls/access/identity-management/ACC.IDM.002_offboarding.md index 88fd1e924..d1c58e5a7 100644 --- a/controls/access/identity-management/ACC.IDM.002_offboarding.md +++ b/controls/access/identity-management/ACC.IDM.002_offboarding.md @@ -11,23 +11,22 @@ frameworks: ## Purpose -Yes, people will leave your company (either by your decision or -theirs). And you want to be prepare! If an early employee leaves and -you forgot to change the ownership on his/her document, you might lose -the documents. +Yes, people will leave your company (either by your decision or theirs). And you +want to be prepare! If an early employee leaves and you forgot to change the +ownership on his/her document, you might lose the documents. -Also, you want to be sure people can’t access the company data or -systems once they left! +Also, you want to be sure people can’t access the company data or systems once +they left! ## Implementation - 1. Integrate the following elements in your offboarding checklist: + - Return of company assets (laptop etc.) - Transfer ownership of documents - Revoke all access to systems - (if you don't have an offboarding checklist → [Offboarding admin checklist](data/offboarding-admin-checklist.md)) + (if you don't have an offboarding checklist → + [Offboarding admin checklist](data/offboarding-admin-checklist.md)) -2. Upload a screenshot of your checklist that contains those bullet - points below +2. Upload a screenshot of your checklist that contains those bullet points below diff --git a/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md b/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md index 8c5703388..c74440768 100644 --- a/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md +++ b/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md @@ -12,18 +12,18 @@ frameworks: ## Purpose When recruiting someone, you want to be sure of who you are hiring: by -performing reference checks (it can also be background checks), you -add an additional layer of certainty on the candidate by looking for -potential red flags in the candidate’s past (history of unethical -behavior, harassment, fraud, etc..). +performing reference checks (it can also be background checks), you add an +additional layer of certainty on the candidate by looking for potential red +flags in the candidate’s past (history of unethical behavior, harassment, fraud, +etc..). ## Implementation -Recruitment is key, especially early stage, so you are probably -already doing it right, it is only about documenting it. +Recruitment is key, especially early stage, so you are probably already doing it +right, it is only about documenting it. -⇒ Define the recruitment process you follow when bringing on a new -member (if you don’t have one formalized, here is a structure: +⇒ Define the recruitment process you follow when bringing on a new member (if +you don’t have one formalized, here is a structure: [Recruitment process](data/recruitment-process.md)). ## Evidence diff --git a/controls/access/identity-management/data/offboarding-admin-checklist.md b/controls/access/identity-management/data/offboarding-admin-checklist.md index 97e4fa9b2..92f219e67 100644 --- a/controls/access/identity-management/data/offboarding-admin-checklist.md +++ b/controls/access/identity-management/data/offboarding-admin-checklist.md @@ -1,9 +1,9 @@ -- [ ] 💰 Make sure we closed the contract on Payfit -- [ ] 💻 Get back and Reset laptop -- [ ] 🔁 Transfert the docs ownership in Google -- [ ] 📧 Suppress the Google account -- [ ] 🖋 Disconnect manually Notion -- [ ] 🛠 Disconnect Slack -- [ ] 🔐 Delete from 1 Password (not suspended, billed) -- [ ] 🗄 Disconnect manually Github -- [ ] 🧐 Double check with the manager for important tool +- [ ] 💰 Make sure we closed the contract on Payfit +- [ ] 💻 Get back and Reset laptop +- [ ] 🔁 Transfert the docs ownership in Google +- [ ] 📧 Suppress the Google account +- [ ] 🖋 Disconnect manually Notion +- [ ] 🛠 Disconnect Slack +- [ ] 🔐 Delete from 1 Password (not suspended, billed) +- [ ] 🗄 Disconnect manually Github +- [ ] 🧐 Double check with the manager for important tool diff --git a/controls/access/identity-management/data/onboarding-for-new-joiner.md b/controls/access/identity-management/data/onboarding-for-new-joiner.md index 979ec84c5..b71fe24e4 100644 --- a/controls/access/identity-management/data/onboarding-for-new-joiner.md +++ b/controls/access/identity-management/data/onboarding-for-new-joiner.md @@ -2,34 +2,34 @@ ## 💜 Welcome! We're so glad to have you 😃 -This first week will be about discovery: discovering the team, the way -we work, and what we do. +This first week will be about discovery: discovering the team, the way we work, +and what we do. -> 💡Here is a checklist to help you settle down. Feel free to navigate -> notion & slack, or to ask questions to anyone. Our role is to make -> your first days as easy as possible. +> 💡Here is a checklist to help you settle down. Feel free to navigate notion & +> slack, or to ask questions to anyone. Our role is to make your first days as +> easy as possible. ## 🆕 Setting you up -- [ ] Log in to your Google Account (you must have received an email) and set up a new password -- [ ] Download Google Authenticator app for 2-factor auth -- [ ] Set-up the 2-factor auth: it is mandatory -- [ ] Log in to 1password -- [ ] Log in to Slack with your google account -- [ ] Log in to Notion with your google account -- [ ] Complete Albert security training on Slack +- [ ] Log in to your Google Account (you must have received an email) and set up + a new password +- [ ] Download Google Authenticator app for 2-factor auth +- [ ] Set-up the 2-factor auth: it is mandatory +- [ ] Log in to 1password +- [ ] Log in to Slack with your google account +- [ ] Log in to Notion with your google account +- [ ] Complete Albert security training on Slack ## 👷 Your Onboarding Project > You’re now ready to present yourself to the team! - -- [ ] Share a few things about you in #all_people in Slack: who are -you, where do you come from, what was your journey until now, whatever -fun fact you’d like to share with us, … you can draw some inspiration -by looking at the previous ones 🙂 -- [ ] Read our Code of Conduct -- [ ] Put a picture of yourself on Slack +- [ ] Share a few things about you in #all_people in Slack: who are you, where + do you come from, what was your journey until now, whatever fun fact you’d + like to share with us, … you can draw some inspiration by looking at the + previous ones 🙂 +- [ ] Read our Code of Conduct +- [ ] Put a picture of yourself on Slack ## 👥 Users @@ -39,10 +39,10 @@ If you want to know more about our users, go check XXXX **Meet the team 🤝** -- [ ] Join the #coffee-chats channel for random coffee breaks -- [ ] Schedule a chat with every member of your team to get to know them 💜 +- [ ] Join the #coffee-chats channel for random coffee breaks +- [ ] Schedule a chat with every member of your team to get to know them 💜 **Understand what we do ❓** -- [ ] Take some time to navigate on our Notion pages 🧭 -- [ ] Get your access to our product to play with it - follow the guide XXXX +- [ ] Take some time to navigate on our Notion pages 🧭 +- [ ] Get your access to our product to play with it - follow the guide XXXX diff --git a/controls/access/identity-management/data/recruitment-process.md b/controls/access/identity-management/data/recruitment-process.md index 8a11eada4..f1f4d61e4 100644 --- a/controls/access/identity-management/data/recruitment-process.md +++ b/controls/access/identity-management/data/recruitment-process.md @@ -3,7 +3,8 @@ 3. Home assignment - 3/4h 4. Assignment review (with hiring manager and one team member) - 1h 5. Check-in call (with talent partner) -15min -6. Final interviews: culture fit and deep dive (5 team members and a founder) - 2x30min + 1h +6. Final interviews: culture fit and deep dive (5 team members and a founder) - + 2x30min + 1h 7. Reference checks - variable, based on position 8. Offer call (with talent partner) - 30min 9. Hire