Add ACC.IDM

Signed-off-by: Bryan Frimin <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-10 16:15:35 +01:00
parent 501fd4cd5a
commit cc6efed46f
6 changed files with 174 additions and 0 deletions

View File

@@ -0,0 +1,41 @@
---
id: "ACC-IDM-001"
category: "access/identity-management"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.3"]
---
## Purpose
It is the perfect timing to ensure that every employees has:
- accepted and signed all documents
- the access needed to perform his/her tasks
- started his/her security training
## Implementation
In theory, you already have an onboarding plan for your new employees
(if not, Onboarding for new
joiner](data/onboarding-for-new-joiner.md)) and a to-do for your admin
running the onboarding (if not, [Onboarding admin
checklist](data/onboarding-admin-checklist.md)).
On your employee to-do, be sure to include:
- Set-up of 2FA
- Set-up of password manager
- Read & acknowledge all policies (it can be part of the contract)
- Complete the security training
On your admin to-do, be sure to include:
- contract is signed before granting access
- apply “least privilege principle” for access (the matrix you defined)
- Force the set-up of 2FA and password manager
- Initiate the security training
## Evidence
- Screenshots of a completed onboarding checklists.

View File

@@ -0,0 +1,33 @@
---
id: "ACC-IDM-002"
category: "access/identity-management"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
frameworks:
- name: "soc2"
sections: ["CC5.3", "CC6.2", "CC6.5"]
---
## Purpose
Yes, people will leave your company (either by your decision or
theirs). And you want to be prepare! If an early employee leaves and
you forgot to change the ownership on his/her document, you might lose
the documents.
Also, you want to be sure people cant access the company data or
systems once they left!
## Implementation
1. Integrate the following elements in your offboarding checklist:
- Return of company assets (laptop etc.)
- Transfer ownership of documents
- Revoke all access to systems
(if you don't have an offboarding checklist → [Offboarding admin checklist](data/offboarding-admin-checklist.md))
2. Upload a screenshot of your checklist that contains those bullet
points below

View File

@@ -0,0 +1,34 @@
---
id: "ACC-IDM-003"
category: "access/identity-management"
revision-version: 1
revision-date: "2024-01-10"
estimate-time: "30m"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.3"]
---
## Purpose
When recruiting someone, you want to be sure of who you are hiring: by
performing reference checks (it can also be background checks), you
add an additional layer of certainty on the candidate by looking for
potential red flags in the candidates past (history of unethical
behavior, harassment, fraud, etc..).
## Implementation
Recruitment is key, especially early stage, so you are probably
already doing it right, it is only about documenting it.
⇒ Define the recruitment process you follow when bringing on a new
member (if you dont have one formalized, here is a structure:
[Recruitment process](data/recruitment-process.md)).
## Evidence
- Reference check template
- Completed check records (redacted)
- Process documentation
- Verification records

View File

@@ -0,0 +1,9 @@
- [ ] 💰 Make sure we closed the contract on Payfit
- [ ] 💻 Get back and Reset laptop
- [ ] 🔁 Transfert the docs ownership in Google
- [ ] 📧 Suppress the Google account
- [ ] 🖋 Disconnect manually Notion
- [ ] 🛠 Disconnect Slack
- [ ] 🔐 Delete from 1 Password (not suspended, billed)
- [ ] 🗄 Disconnect manually Github
- [ ] 🧐 Double check with the manager for important tool

View File

@@ -0,0 +1,48 @@
# Onboarding for new joiner
## 💜 Welcome! We're so glad to have you 😃
This first week will be about discovery: discovering the team, the way
we work, and what we do.
> 💡Here is a checklist to help you settle down. Feel free to navigate
> notion & slack, or to ask questions to anyone. Our role is to make
> your first days as easy as possible.
## 🆕 Setting you up
- [ ] Log in to your Google Account (you must have received an email) and set up a new password
- [ ] Download Google Authenticator app for 2-factor auth
- [ ] Set-up the 2-factor auth: it is mandatory
- [ ] Log in to 1password
- [ ] Log in to Slack with your google account
- [ ] Log in to Notion with your google account
- [ ] Complete Albert security training on Slack
## 👷 Your Onboarding Project
> Youre now ready to present yourself to the team!
-[ ] Share a few things about you in #all_people in Slack: who are
you, where do you come from, what was your journey until now, whatever
fun fact youd like to share with us, … you can draw some inspiration
by looking at the previous ones 🙂
- [ ] Read our Code of Conduct
- [ ] Put a picture of yourself on Slack
## 👥 Users
If you want to know more about our users, go check XXXX
## 🚀 To go further
**Meet the team 🤝**
- [ ] Join the #coffee-chats channel for random coffee breaks
- [ ] Schedule a chat with every member of your team to get to know them 💜
**Understand what we do ❓**
- [ ] Take some time to navigate on our Notion pages 🧭
- [ ] Get your access to our product to play with it - follow the guide XXXX

View File

@@ -0,0 +1,9 @@
1. Initial screen (with talent partner) - 30min
2. Technical interview (with hiring manager) - 30min/1h
3. Home assignment - 3/4h
4. Assignment review (with hiring manager and one team member) - 1h
5. Check-in call (with talent partner) -15min
6. Final interviews: culture fit and deep dive (5 team members and a founder) - 2x30min + 1h
7. Reference checks - variable, based on position
8. Offer call (with talent partner) - 30min
9. Hire