From cc6efed46f8189982eeff9086510669aded13c2d Mon Sep 17 00:00:00 2001 From: gearnode Date: Fri, 10 Jan 2025 16:15:35 +0100 Subject: [PATCH] Add ACC.IDM Signed-off-by: Bryan Frimin --- .../ACC.IDM.001_onboarding.md | 41 ++++++++++++++++ .../ACC.IDM.002_offboarding.md | 33 +++++++++++++ ...DM.003_pre-employment-screening-process.md | 34 +++++++++++++ .../data/offboarding-admin-checklist.md | 9 ++++ .../data/onboarding-for-new-joiner.md | 48 +++++++++++++++++++ .../data/recruitment-process.md | 9 ++++ 6 files changed, 174 insertions(+) create mode 100644 controls/access/identity-management/ACC.IDM.001_onboarding.md create mode 100644 controls/access/identity-management/ACC.IDM.002_offboarding.md create mode 100644 controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md create mode 100644 controls/access/identity-management/data/offboarding-admin-checklist.md create mode 100644 controls/access/identity-management/data/onboarding-for-new-joiner.md create mode 100644 controls/access/identity-management/data/recruitment-process.md diff --git a/controls/access/identity-management/ACC.IDM.001_onboarding.md b/controls/access/identity-management/ACC.IDM.001_onboarding.md new file mode 100644 index 000000000..f154b190c --- /dev/null +++ b/controls/access/identity-management/ACC.IDM.001_onboarding.md @@ -0,0 +1,41 @@ +--- +id: "ACC-IDM-001" +category: "access/identity-management" +revision-version: 1 +revision-date: "2024-01-10" +estimate-time: "30m" +frameworks: + - name: "soc2" + sections: ["CC1.4", "CC5.3"] +--- + +## Purpose + +It is the perfect timing to ensure that every employees has: +- accepted and signed all documents +- the access needed to perform his/her tasks +- started his/her security training + +## Implementation + +In theory, you already have an onboarding plan for your new employees +(if not, Onboarding for new +joiner](data/onboarding-for-new-joiner.md)) and a to-do for your admin +running the onboarding (if not, [Onboarding admin +checklist](data/onboarding-admin-checklist.md)). + +On your employee to-do, be sure to include: +- Set-up of 2FA +- Set-up of password manager +- Read & acknowledge all policies (it can be part of the contract) +- Complete the security training + +On your admin to-do, be sure to include: +- contract is signed before granting access +- apply “least privilege principle” for access (the matrix you defined) +- Force the set-up of 2FA and password manager +- Initiate the security training + +## Evidence + +- Screenshots of a completed onboarding checklists. diff --git a/controls/access/identity-management/ACC.IDM.002_offboarding.md b/controls/access/identity-management/ACC.IDM.002_offboarding.md new file mode 100644 index 000000000..88fd1e924 --- /dev/null +++ b/controls/access/identity-management/ACC.IDM.002_offboarding.md @@ -0,0 +1,33 @@ +--- +id: "ACC-IDM-002" +category: "access/identity-management" +revision-version: 1 +revision-date: "2024-01-10" +estimate-time: "30m" +frameworks: + - name: "soc2" + sections: ["CC5.3", "CC6.2", "CC6.5"] +--- + +## Purpose + +Yes, people will leave your company (either by your decision or +theirs). And you want to be prepare! If an early employee leaves and +you forgot to change the ownership on his/her document, you might lose +the documents. + +Also, you want to be sure people can’t access the company data or +systems once they left! + +## Implementation + + +1. Integrate the following elements in your offboarding checklist: + - Return of company assets (laptop etc.) + - Transfer ownership of documents + - Revoke all access to systems + + (if you don't have an offboarding checklist → [Offboarding admin checklist](data/offboarding-admin-checklist.md)) + +2. Upload a screenshot of your checklist that contains those bullet + points below diff --git a/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md b/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md new file mode 100644 index 000000000..8c5703388 --- /dev/null +++ b/controls/access/identity-management/ACC.IDM.003_pre-employment-screening-process.md @@ -0,0 +1,34 @@ +--- +id: "ACC-IDM-003" +category: "access/identity-management" +revision-version: 1 +revision-date: "2024-01-10" +estimate-time: "30m" +frameworks: + - name: "soc2" + sections: ["CC1.4", "CC5.3"] +--- + +## Purpose + +When recruiting someone, you want to be sure of who you are hiring: by +performing reference checks (it can also be background checks), you +add an additional layer of certainty on the candidate by looking for +potential red flags in the candidate’s past (history of unethical +behavior, harassment, fraud, etc..). + +## Implementation + +Recruitment is key, especially early stage, so you are probably +already doing it right, it is only about documenting it. + +⇒ Define the recruitment process you follow when bringing on a new +member (if you don’t have one formalized, here is a structure: +[Recruitment process](data/recruitment-process.md)). + +## Evidence + +- Reference check template +- Completed check records (redacted) +- Process documentation +- Verification records diff --git a/controls/access/identity-management/data/offboarding-admin-checklist.md b/controls/access/identity-management/data/offboarding-admin-checklist.md new file mode 100644 index 000000000..97e4fa9b2 --- /dev/null +++ b/controls/access/identity-management/data/offboarding-admin-checklist.md @@ -0,0 +1,9 @@ +- [ ] 💰 Make sure we closed the contract on Payfit +- [ ] 💻 Get back and Reset laptop +- [ ] 🔁 Transfert the docs ownership in Google +- [ ] 📧 Suppress the Google account +- [ ] 🖋 Disconnect manually Notion +- [ ] 🛠 Disconnect Slack +- [ ] 🔐 Delete from 1 Password (not suspended, billed) +- [ ] 🗄 Disconnect manually Github +- [ ] 🧐 Double check with the manager for important tool diff --git a/controls/access/identity-management/data/onboarding-for-new-joiner.md b/controls/access/identity-management/data/onboarding-for-new-joiner.md new file mode 100644 index 000000000..fe5f47769 --- /dev/null +++ b/controls/access/identity-management/data/onboarding-for-new-joiner.md @@ -0,0 +1,48 @@ +# Onboarding for new joiner + +## 💜 Welcome! We're so glad to have you 😃 + +This first week will be about discovery: discovering the team, the way +we work, and what we do. + +> 💡Here is a checklist to help you settle down. Feel free to navigate +> notion & slack, or to ask questions to anyone. Our role is to make +> your first days as easy as possible. + +## 🆕 Setting you up + +- [ ] Log in to your Google Account (you must have received an email) and set up a new password +- [ ] Download Google Authenticator app for 2-factor auth +- [ ] Set-up the 2-factor auth: it is mandatory +- [ ] Log in to 1password +- [ ] Log in to Slack with your google account +- [ ] Log in to Notion with your google account +- [ ] Complete Albert security training on Slack + +## 👷 Your Onboarding Project + +> You’re now ready to present yourself to the team! + + +-[ ] Share a few things about you in #all_people in Slack: who are +you, where do you come from, what was your journey until now, whatever +fun fact you’d like to share with us, … you can draw some inspiration +by looking at the previous ones 🙂 +- [ ] Read our Code of Conduct +- [ ] Put a picture of yourself on Slack + +## 👥 Users + +If you want to know more about our users, go check XXXX + +## 🚀 To go further + +**Meet the team 🤝** + +- [ ] Join the #coffee-chats channel for random coffee breaks +- [ ] Schedule a chat with every member of your team to get to know them 💜 + +**Understand what we do ❓** + +- [ ] Take some time to navigate on our Notion pages 🧭 +- [ ] Get your access to our product to play with it - follow the guide XXXX diff --git a/controls/access/identity-management/data/recruitment-process.md b/controls/access/identity-management/data/recruitment-process.md new file mode 100644 index 000000000..8a11eada4 --- /dev/null +++ b/controls/access/identity-management/data/recruitment-process.md @@ -0,0 +1,9 @@ +1. Initial screen (with talent partner) - 30min +2. Technical interview (with hiring manager) - 30min/1h +3. Home assignment - 3/4h +4. Assignment review (with hiring manager and one team member) - 1h +5. Check-in call (with talent partner) -15min +6. Final interviews: culture fit and deep dive (5 team members and a founder) - 2x30min + 1h +7. Reference checks - variable, based on position +8. Offer call (with talent partner) - 30min +9. Hire