From 68c003ac6dfbf0ed1dd7de26eb1f2caff6dd7fad Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 19:11:02 +0000 Subject: [PATCH 01/14] feat: add Code of Conduct policy document --- .../src/jobs/seed/policies/codeofconduct.json | 182 ++++++++++++++++++ 1 file changed, 182 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/codeofconduct.json diff --git a/apps/app/src/jobs/seed/policies/codeofconduct.json b/apps/app/src/jobs/seed/policies/codeofconduct.json new file mode 100644 index 0000000000..9ae031c24e --- /dev/null +++ b/apps/app/src/jobs/seed/policies/codeofconduct.json @@ -0,0 +1,182 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC1.1", "CC1.5"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Code of Conduct Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Human Resources" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to define expected behavior from employees towards their colleagues, supervisors, and the organization as a whole." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All employees and contractors must follow this policy as outlined in their Employment Offer Letter or Independent Contractor Agreement while performing their duties." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Compliance with Law: Employees must understand and comply with environmental, safety, and fair dealing laws while ensuring ethical and responsible conduct in their job duties." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Respect in the Workplace: Discriminatory behavior, harassment, or victimization is strictly prohibited." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Protection of Company Property: Employees must not misuse company equipment, respect intellectual property, and protect material property from damage." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Personal Appearance: Employees must present themselves in a professional manner and adhere to the company dress code." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Corruption: Employees must not accept bribes or inappropriate gifts from clients or partners." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Job Duties and Authority: Employees must act with integrity, respect team members, and avoid abuse of authority when delegating responsibilities." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Absenteeism and Tardiness: Employees must adhere to their designated work schedules unless exceptions are approved by their hiring manager." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Conflict of Interest: Employees must avoid personal or financial interests that interfere with their job duties." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Collaboration: Employees must promote a positive and cooperative work environment." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Communication: Employees must maintain open and professional communication with colleagues and supervisors." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Benefits: Employees must not abuse employment benefits, such as time off, insurance, or company resources." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Policy Adherence: Employees must comply with all company policies. Questions should be directed to HR or their hiring manager." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Disciplinary Actions" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Violations of this policy may result in disciplinary actions, including but not limited to:" }] }, + { + "type": "bulletList", + "content": [ + { "type": "listItem", "content": [{ "type": "text", "text": "Demotion" }] }, + { "type": "listItem", "content": [{ "type": "text", "text": "Reprimand" }] }, + { "type": "listItem", "content": [{ "type": "text", "text": "Suspension or termination" }] }, + { "type": "listItem", "content": [{ "type": "text", "text": "Reduction of benefits" }] } + ] + } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Serious violations such as corruption, theft, or embezzlement may result in legal action." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From 8dbcce7958978ac29fdfb9f0694c14d5d4f50445 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 19:14:52 +0000 Subject: [PATCH 02/14] feat: add Third-Party Management Policy document --- .../src/jobs/seed/policies/thirdparty.json | 168 ++++++++++++++++++ 1 file changed, 168 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/thirdparty.json diff --git a/apps/app/src/jobs/seed/policies/thirdparty.json b/apps/app/src/jobs/seed/policies/thirdparty.json new file mode 100644 index 0000000000..17c3aad9dc --- /dev/null +++ b/apps/app/src/jobs/seed/policies/thirdparty.json @@ -0,0 +1,168 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC8.1", "CC9.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Third-Party Management Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy defines the rules for relationships with the organization’s Information Technology (IT) third-parties and partners." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all IT third-parties and partners who can impact the confidentiality, integrity, and availability of the organization’s technology and sensitive information, or who are within the scope of the organization’s information security program." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees and contractors responsible for the management and oversight of IT third-parties and partners of the organization." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Background" }] + }, + { + "type": "paragraph", + "content": [ + { + "type": "text", + "text": "The overall security of the organization is highly dependent on the security of its contractual relationships with its IT suppliers and partners. This policy defines requirements for effective management and oversight of such suppliers and partners from an information security perspective. It prescribes minimum security standards third-parties must meet, including security clauses, risk assessments, service level agreements, and incident management." + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "References" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Information Security Policy" }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Security Incident Response Policy" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "IT third-parties are prohibited from accessing the organization’s information security assets until a contract containing security controls is agreed to and signed by the appropriate parties." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All IT third-parties must comply with the security policies defined in the Information Security Policy." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All security incidents involving IT third-parties or partners must be documented per the Security Incident Response Policy and immediately reported to the Information Security Manager (ISM)." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must adhere to the terms of all Service Level Agreements (SLAs) entered into with IT third-parties. As SLAs are updated or new agreements are made, necessary changes or controls must be implemented to maintain compliance." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Before entering into a contract and gaining access to the organization’s information systems, IT third-parties must undergo a risk assessment." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Security risks related to IT third-parties and partners must be identified during the risk assessment process, including risks related to IT third-party supply chains and sub-suppliers." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "IT third-parties and partners must ensure that organizational records are protected, safeguarded, and securely disposed of in accordance with legal, regulatory, and contractual requirements regarding the collection, processing, and transmission of sensitive data such as Personally-Identifiable Information (PII)." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization reserves the right to audit IT third-parties and partners to ensure compliance with applicable security policies, legal requirements, regulatory standards, and contractual obligations." }] } + ] + } + ] + } + ] + } From 8a8e5a5db4b2a3980f73e22cb0fdb13d5fa41b2a Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 19:16:40 +0000 Subject: [PATCH 03/14] feat: add Workstation Policy document --- .../src/jobs/seed/policies/workstation.json | 206 ++++++++++++++++++ 1 file changed, 206 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/workstation.json diff --git a/apps/app/src/jobs/seed/policies/workstation.json b/apps/app/src/jobs/seed/policies/workstation.json new file mode 100644 index 0000000000..fb496980d0 --- /dev/null +++ b/apps/app/src/jobs/seed/policies/workstation.json @@ -0,0 +1,206 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC6.1", "CC6.2"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Workstation Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy defines best practices to reduce the risk of data loss or exposure through workstations." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees and contractors using workstations." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Workstations are defined as all company-owned and personal devices containing company data." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 3 }, + "content": [{ "type": "text", "text": "Workstation Device Requirements" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Operating systems must be no more than one generation older than the current version." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Devices must be encrypted at rest to protect company data." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Devices must be locked when not in use or when an employee leaves the workstation." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Workstations must be used for authorized business purposes only." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Loss or destruction of devices must be reported immediately to IT." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Laptops and desktop devices must run the latest version of IT-approved antivirus software." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 3 }, + "content": [{ "type": "text", "text": "Desktop & Laptop Devices" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Employees will be issued a desktop, laptop, or both based on their job duties." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Contractors must provide their own laptops." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Desktops and laptops must operate on macOS or Windows." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 3 }, + "content": [{ "type": "text", "text": "Mobile Devices" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Mobile devices must be operated as defined in the Removable Media Policy, Cloud Storage Policy, and Bring Your Own Device (BYOD) Policy." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Mobile devices must operate on iOS or Android." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Company data may only be accessed on mobile devices using Slack and Gmail." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 3 }, + "content": [{ "type": "text", "text": "Removable Media" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Removable media must be used as defined in the Removable Media Policy, Cloud Storage Policy, and Bring Your Own Device (BYOD) Policy." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Removable media is permitted on approved devices as long as it does not conflict with other policies." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From 9fc773b8cbf7646c574a64b691af3840ef19298d Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 20:08:33 +0000 Subject: [PATCH 04/14] feat: update availability policy controls to include A1.1 and A1.2 --- apps/app/src/jobs/seed/policies/availability.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/app/src/jobs/seed/policies/availability.json b/apps/app/src/jobs/seed/policies/availability.json index 8f39728f7e..cb50518958 100644 --- a/apps/app/src/jobs/seed/policies/availability.json +++ b/apps/app/src/jobs/seed/policies/availability.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC9.1"] + "controls": ["CC9.1", "A1.1", "A1.2"] }, "content": [ { From 5bad5361c11a4a05e1071c8ce1a47d60c2f55372 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 20:08:40 +0000 Subject: [PATCH 05/14] feat: add CC6.8 and A1.1 controls to policy metadata --- apps/app/src/jobs/seed/policies/change.json | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/apps/app/src/jobs/seed/policies/change.json b/apps/app/src/jobs/seed/policies/change.json index 5ebe8bf61e..4c11778b92 100644 --- a/apps/app/src/jobs/seed/policies/change.json +++ b/apps/app/src/jobs/seed/policies/change.json @@ -3,7 +3,9 @@ "metadata": { "controls": [ "CC8.1", - "CC3.4" + "CC3.4", + "CC6.8", + "A1.1" ] }, "content": [ From c9df3a0ea6d1ef2fb2b2d6a8c9081e2d2e1b0a30 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 20:08:45 +0000 Subject: [PATCH 06/14] feat: add Confidentiality Policy document with controls CC9.9 and CC8.1 --- .../jobs/seed/policies/confidentiality.json | 194 ++++++++++++++++++ 1 file changed, 194 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/confidentiality.json diff --git a/apps/app/src/jobs/seed/policies/confidentiality.json b/apps/app/src/jobs/seed/policies/confidentiality.json new file mode 100644 index 0000000000..63719b4192 --- /dev/null +++ b/apps/app/src/jobs/seed/policies/confidentiality.json @@ -0,0 +1,194 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC9.9", "CC8.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Confidentiality Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to define guidelines for maintaining the confidentiality of sensitive and proprietary information within the organization." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, third-party vendors, and other individuals who access confidential information belonging to the organization." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Confidential information includes, but is not limited to, customer data, trade secrets, intellectual property, financial records, employee records, and other sensitive organizational data." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Confidential Information Handling" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Confidential information must be accessed only by authorized individuals with a legitimate business need." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Confidential data must be encrypted at rest and in transit to prevent unauthorized access." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Employees must use company-approved systems and communication channels for handling confidential data." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Unauthorized disclosure, duplication, or transmission of confidential data is strictly prohibited." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Non-Disclosure Agreements (NDAs)" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All employees, contractors, and third-party vendors must sign a Non-Disclosure Agreement (NDA) before accessing confidential information." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "NDAs outline obligations to protect and prevent the unauthorized use or disclosure of confidential information." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Violations of an NDA may result in disciplinary action, contract termination, and potential legal consequences." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Access Control Measures" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Access to confidential information is based on the principle of least privilege (PoLP)." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Users must authenticate via company-approved methods (e.g., Multi-Factor Authentication) before accessing confidential data." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Confidential data must not be stored on personal devices unless explicitly authorized." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Incident Reporting and Enforcement" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Employees must report any suspected or actual breaches of confidentiality to the Information Security Manager (ISM) immediately." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Violations of this policy may result in disciplinary actions, including termination of employment or legal action." }] } + ] + } + ] + } + ] + } + + + + + + \ No newline at end of file From f3972b6c285f6da573051a3915179b2d3f8b6db4 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 20:08:50 +0000 Subject: [PATCH 07/14] feat: add Data Classification Policy document with controls CC9.9 and CC8.1 --- .../seed/policies/dataclassification.json | 164 ++++++++++++++++++ 1 file changed, 164 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/dataclassification.json diff --git a/apps/app/src/jobs/seed/policies/dataclassification.json b/apps/app/src/jobs/seed/policies/dataclassification.json new file mode 100644 index 0000000000..22c00b6fef --- /dev/null +++ b/apps/app/src/jobs/seed/policies/dataclassification.json @@ -0,0 +1,164 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC9.9", "CC8.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Data Classification Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to establish guidelines for classifying, labeling, and handling data within the organization to ensure appropriate protection and compliance with legal, regulatory, and contractual requirements." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, and third parties who access, handle, or manage the organization’s data." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All data within the organization, including electronic and physical records, falls under the scope of this policy." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Data Classification Levels" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "Classification Level" }] }, + { "type": "tableCell", "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "Description" }] }, + { "type": "tableCell", "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "Access Restrictions" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Public" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Information intended for public release that does not pose any risk to the organization if disclosed." }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Accessible to everyone." }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Internal Use" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Non-sensitive business information intended for internal use only." }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Accessible to employees and authorized third parties." }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Restricted" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Sensitive business information that could cause harm to the organization if disclosed." }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Accessible only to authorized personnel with a need-to-know basis." }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Highly sensitive information that could cause significant damage to the organization if disclosed." }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Strictly limited to specific individuals and requires additional security measures." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Data Handling Requirements" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Classified information must be labeled according to its classification level." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Data must be protected in transit and at rest based on its classification." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Access to classified information must be controlled based on the principle of least privilege." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Confidential data must be encrypted and stored in secure locations." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Employees handling classified data must adhere to security and compliance guidelines." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From 1856b13ebd8f4ab6ff6c41ef90313e6d62149df7 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 22:53:40 +0000 Subject: [PATCH 08/14] feat: add Business Continuity Policy document with controls CC9.1 and CC8.1 --- .../seed/policies/businesscontinuity.json | 195 ++++++++++++++++++ 1 file changed, 195 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/businesscontinuity.json diff --git a/apps/app/src/jobs/seed/policies/businesscontinuity.json b/apps/app/src/jobs/seed/policies/businesscontinuity.json new file mode 100644 index 0000000000..7de6a7e9b8 --- /dev/null +++ b/apps/app/src/jobs/seed/policies/businesscontinuity.json @@ -0,0 +1,195 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC9.1", "CC8.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Business Continuity Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to establish a framework for business continuity planning to ensure the organization can maintain operations during and after a disruptive event." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, and third parties involved in business continuity and disaster recovery processes." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The policy covers preparedness, response, recovery, and resumption of critical business functions in the event of a disruption." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Business Continuity Plan (BCP) Requirements" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must establish and maintain a Business Continuity Plan (BCP) to define how business operations will continue during and after an emergency." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The BCP must identify critical business functions, personnel, and infrastructure required for operational continuity." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "BCP testing and exercises must be conducted at least annually to ensure readiness." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All employees must be trained on their roles and responsibilities within the BCP." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Disaster Recovery Planning" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must maintain a Disaster Recovery Plan (DRP) that defines how IT systems, applications, and data will be restored following a disruption." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Backup procedures must be in place to ensure critical business data is recoverable in case of data loss or corruption." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Disaster recovery tests must be conducted at least annually to validate system recovery capabilities." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Incident Response and Communication" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must have an incident response plan outlining procedures for handling security incidents, system failures, or natural disasters." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "A designated Business Continuity Team (BCT) must oversee crisis management and ensure continuity measures are implemented." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Employees must be informed of emergency procedures, including alternative work locations if needed." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Compliance and Review" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The Business Continuity Policy must be reviewed annually and updated as necessary." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must ensure compliance with industry regulations and standards related to business continuity and disaster recovery." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Non-compliance with this policy may result in corrective actions, including training, enhanced security controls, or disciplinary measures." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From e733194f216ae815e759aba6963ace979c66e615 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 22:53:48 +0000 Subject: [PATCH 09/14] feat: add Risk Assessment Policy document with controls CC9.1 and CC8.1 --- .../jobs/seed/policies/riskassessment.json | 166 ++++++++++++++++++ 1 file changed, 166 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/riskassessment.json diff --git a/apps/app/src/jobs/seed/policies/riskassessment.json b/apps/app/src/jobs/seed/policies/riskassessment.json new file mode 100644 index 0000000000..182473b981 --- /dev/null +++ b/apps/app/src/jobs/seed/policies/riskassessment.json @@ -0,0 +1,166 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC9.1", "CC8.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Risk Assessment Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to establish a structured approach for identifying, evaluating, and mitigating risks associated with the organization's information systems, operations, and assets." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, and third parties responsible for assessing and managing risk within the organization." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Risk assessments must be conducted for all business units, departments, and critical systems to ensure compliance with regulatory and security requirements." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Risk Assessment Process" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must establish a formal risk assessment methodology that includes identifying assets, assessing threats, determining vulnerabilities, and evaluating impact and likelihood." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All risks must be documented in a risk register and categorized based on their severity and potential business impact." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Risk assessments must be conducted at least annually and whenever significant changes to systems, processes, or threats occur." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All identified risks must be assigned an owner responsible for implementing appropriate mitigation measures." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Risk Mitigation Strategies" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must implement risk mitigation strategies based on the level of identified risk, including risk avoidance, acceptance, transfer, and reduction." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Controls must be implemented to reduce risk to an acceptable level, including security controls, process improvements, and technical safeguards." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Risk treatment plans must be reviewed periodically to ensure continued effectiveness." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Reporting and Review" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Risk assessment results must be reported to senior management and stakeholders to ensure informed decision-making." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Risk management activities must be reviewed and updated periodically to adapt to emerging threats and business changes." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Non-compliance with the risk assessment policy may result in corrective actions, including additional training, enhanced security controls, or disciplinary measures." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From c571158d29722efc3812c24fd1b360547043fc09 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 22:54:05 +0000 Subject: [PATCH 10/14] feat: add Cyber Risk Assessment Policy document with controls CC9.1 and CC8.1 --- .../app/src/jobs/seed/policies/cyberrisk.json | 172 ++++++++++++++++++ 1 file changed, 172 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/cyberrisk.json diff --git a/apps/app/src/jobs/seed/policies/cyberrisk.json b/apps/app/src/jobs/seed/policies/cyberrisk.json new file mode 100644 index 0000000000..e6fb8168cb --- /dev/null +++ b/apps/app/src/jobs/seed/policies/cyberrisk.json @@ -0,0 +1,172 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC9.1", "CC8.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Cyber Risk Assessment Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to establish a structured approach for conducting cyber risk assessments to identify, evaluate, and mitigate cybersecurity threats to the organization." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, and third parties responsible for cybersecurity risk management within the organization." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Cyber risk assessments must be conducted on all critical systems, networks, and applications to ensure compliance with security policies and regulatory requirements." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Cyber Risk Assessment Process" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must establish a cyber risk assessment methodology that includes identifying assets, assessing threats, evaluating vulnerabilities, and determining potential impact." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All risks must be documented in a cyber risk register and categorized based on severity and business impact." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Cyber risk assessments must be conducted at least annually and whenever significant changes to the IT infrastructure or threat landscape occur." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Identified risks must be assigned an owner responsible for implementing appropriate mitigation measures." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Cyber Risk Mitigation Strategies" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must implement cyber risk mitigation strategies based on the severity of identified risks, including risk avoidance, acceptance, transfer, or reduction." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Cybersecurity controls such as firewalls, encryption, endpoint protection, and access controls must be implemented to reduce risk to an acceptable level." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Cyber risk treatment plans must be reviewed periodically to ensure their continued effectiveness." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Reporting and Compliance" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Cyber risk assessment results must be reported to senior management and cybersecurity stakeholders for informed decision-making." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must comply with industry standards, regulations, and best practices for cybersecurity risk management." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Cyber risk assessments must be updated periodically to adapt to evolving cyber threats and business changes." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Non-compliance with this policy may result in corrective actions, including enhanced security controls, additional training, or disciplinary measures." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From 7610fa8a1ac8561894b418b1ab243c7733e32fac Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 23:34:34 +0000 Subject: [PATCH 11/14] feat: add Datacenter Policy document with controls --- .../src/jobs/seed/policies/datacenter.json | 195 ++++++++++++++++++ 1 file changed, 195 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/datacenter.json diff --git a/apps/app/src/jobs/seed/policies/datacenter.json b/apps/app/src/jobs/seed/policies/datacenter.json new file mode 100644 index 0000000000..e41467c409 --- /dev/null +++ b/apps/app/src/jobs/seed/policies/datacenter.json @@ -0,0 +1,195 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC6.1", "CC6.2", "CC9.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Datacenter Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to define security and operational requirements for the organization's datacenter facilities to ensure protection, availability, and reliability of critical systems and data." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, vendors, and third-party service providers who access or maintain datacenter infrastructure." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All datacenter locations, including on-premises, colocation, and cloud facilities that host the organization's critical IT infrastructure, fall under this policy's scope." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Datacenter Security Requirements" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Datacenters must have physical security controls such as access restrictions, video surveillance, and intrusion detection systems." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Access to the datacenter must be granted only to authorized personnel with a legitimate business need." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Visitor access must be logged, monitored, and restricted to authorized escorts within the facility." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Multi-factor authentication must be required for personnel accessing restricted areas of the datacenter." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Environmental Controls" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Datacenters must have redundant power supplies and backup generators to ensure continuous operation." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Temperature and humidity must be monitored and maintained within manufacturer-recommended ranges for critical equipment." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Fire suppression systems must be in place to protect against damage to IT infrastructure." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Datacenter Access and Auditing" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Access logs must be maintained and reviewed periodically to ensure compliance with access control policies." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Annual security assessments must be conducted to evaluate compliance with datacenter security requirements." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Unauthorized access attempts must be reported immediately to security personnel." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Disaster Recovery and Business Continuity" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Datacenter facilities must be included in the organization's Business Continuity and Disaster Recovery plans." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Data backups must be stored securely and regularly tested to ensure data recoverability." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Datacenter failover plans must be documented and tested periodically." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From db2d6ab410f84f3c7ca384f87c49186ba09ad2d7 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Mon, 10 Feb 2025 23:35:07 +0000 Subject: [PATCH 12/14] feat: add Software Development Lifecycle (SDLC) Policy document with controls --- .../seed/policies/softwaredevelopment.json | 191 ++++++++++++++++++ 1 file changed, 191 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/softwaredevelopment.json diff --git a/apps/app/src/jobs/seed/policies/softwaredevelopment.json b/apps/app/src/jobs/seed/policies/softwaredevelopment.json new file mode 100644 index 0000000000..75881ea51d --- /dev/null +++ b/apps/app/src/jobs/seed/policies/softwaredevelopment.json @@ -0,0 +1,191 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC6.2", "CC8.1", "CC9.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Software Development Lifecycle (SDLC) Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to define a structured Software Development Lifecycle (SDLC) to ensure secure, reliable, and high-quality software development practices." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all software development teams, including employees, contractors, and third-party developers involved in designing, developing, testing, deploying, and maintaining software for the organization." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The policy covers all software, including internal applications, customer-facing applications, and third-party integrated software solutions." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Software Development Lifecycle Phases" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { + "type": "paragraph", + "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "1. Planning & Requirements:" }] + }, + { + "type": "paragraph", + "content": [{ "type": "text", "text": "Define business, functional, and security requirements before software development begins. Risk assessments must be conducted to identify security concerns early in the process." }] + } + ] + }, + { + "type": "listItem", + "content": [ + { + "type": "paragraph", + "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "2. Design & Architecture:" }] + }, + { + "type": "paragraph", + "content": [{ "type": "text", "text": "Software design must incorporate security principles, including secure authentication, encryption, and least privilege access controls." }] + } + ] + }, + { + "type": "listItem", + "content": [ + { + "type": "paragraph", + "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "3. Development & Implementation:" }] + }, + { + "type": "paragraph", + "content": [{ "type": "text", "text": "Developers must adhere to secure coding practices, including input validation, proper error handling, and protection against known vulnerabilities (e.g., OWASP Top Ten threats)." }] + } + ] + }, + { + "type": "listItem", + "content": [ + { + "type": "paragraph", + "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "4. Testing & Validation:" }] + }, + { + "type": "paragraph", + "content": [{ "type": "text", "text": "All software must undergo security, functional, and performance testing before deployment. Automated and manual security testing must be conducted, including penetration testing and code reviews." }] + } + ] + }, + { + "type": "listItem", + "content": [ + { + "type": "paragraph", + "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "5. Deployment & Release:" }] + }, + { + "type": "paragraph", + "content": [{ "type": "text", "text": "Deployment processes must be documented and follow controlled release cycles. All code must be reviewed and approved before being deployed to production environments." }] + } + ] + }, + { + "type": "listItem", + "content": [ + { + "type": "paragraph", + "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "6. Maintenance & Continuous Improvement:" }] + }, + { + "type": "paragraph", + "content": [{ "type": "text", "text": "Software must be continuously monitored for vulnerabilities, and security patches must be applied promptly." }] + } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Security & Compliance Requirements" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Secure coding practices must be followed in all phases of development." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Regular security testing must be conducted, including static and dynamic code analysis." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "All software must comply with applicable legal, regulatory, and contractual security requirements." }] } + ] + } + ] + } + ] + } + \ No newline at end of file From 1466415a8a85af359693c718859f7b9da0316cc4 Mon Sep 17 00:00:00 2001 From: "Austin Songer, CISSP" Date: Tue, 11 Feb 2025 00:38:13 +0000 Subject: [PATCH 13/14] feat: update policy documents with new control measures --- apps/app/src/jobs/seed/policies/access.json | 2 +- .../src/jobs/seed/policies/application.json | 2 +- .../src/jobs/seed/policies/availability.json | 2 +- .../seed/policies/businesscontinuity.json | 2 +- apps/app/src/jobs/seed/policies/change.json | 7 +- .../jobs/seed/policies/classification.json | 5 +- .../src/jobs/seed/policies/codeofconduct.json | 2 +- .../jobs/seed/policies/confidentiality.json | 2 +- .../app/src/jobs/seed/policies/cyberrisk.json | 2 +- .../src/jobs/seed/policies/datacenter.json | 2 +- .../seed/policies/dataclassification.json | 164 ------------------ .../jobs/seed/policies/riskassessment.json | 2 +- .../seed/policies/softwaredevelopment.json | 2 +- .../src/jobs/seed/policies/thirdparty.json | 2 +- .../src/jobs/seed/policies/workstation.json | 2 +- 15 files changed, 14 insertions(+), 186 deletions(-) delete mode 100644 apps/app/src/jobs/seed/policies/dataclassification.json diff --git a/apps/app/src/jobs/seed/policies/access.json b/apps/app/src/jobs/seed/policies/access.json index f659860528..9bcf193596 100644 --- a/apps/app/src/jobs/seed/policies/access.json +++ b/apps/app/src/jobs/seed/policies/access.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC6.1", "CC6.2", "CC6.3"] + "controls": ["CC6.1", "CC6.2", "CC6.4", "CC6.8"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/application.json b/apps/app/src/jobs/seed/policies/application.json index 9a16abf0e9..5d6e7d1bda 100644 --- a/apps/app/src/jobs/seed/policies/application.json +++ b/apps/app/src/jobs/seed/policies/application.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC6.2"] + "controls": ["CC7.1", "CC7.2", "CC7.4"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/availability.json b/apps/app/src/jobs/seed/policies/availability.json index cb50518958..f3be042231 100644 --- a/apps/app/src/jobs/seed/policies/availability.json +++ b/apps/app/src/jobs/seed/policies/availability.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC9.1", "A1.1", "A1.2"] + "controls": ["CC9.1","CC7.3", "CC7.5", "A1.1", "A1.2"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/businesscontinuity.json b/apps/app/src/jobs/seed/policies/businesscontinuity.json index 7de6a7e9b8..2135f3ebd1 100644 --- a/apps/app/src/jobs/seed/policies/businesscontinuity.json +++ b/apps/app/src/jobs/seed/policies/businesscontinuity.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC9.1", "CC8.1"] + "controls": ["CC1.4", "CC7.5", "A1.2","A1.3"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/change.json b/apps/app/src/jobs/seed/policies/change.json index 4c11778b92..807030fad6 100644 --- a/apps/app/src/jobs/seed/policies/change.json +++ b/apps/app/src/jobs/seed/policies/change.json @@ -1,12 +1,7 @@ { "type": "doc", "metadata": { - "controls": [ - "CC8.1", - "CC3.4", - "CC6.8", - "A1.1" - ] + "controls": ["CC3.4", "CC6.8", "CC7.1", "A1.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/classification.json b/apps/app/src/jobs/seed/policies/classification.json index c3dd23d79f..37402a5607 100644 --- a/apps/app/src/jobs/seed/policies/classification.json +++ b/apps/app/src/jobs/seed/policies/classification.json @@ -1,10 +1,7 @@ { "type": "doc", "metadata": { - "controls": [ - "CC9.9", - "CC8.1" - ] + "controls": ["CC6.1", "CC8.1","CC6.6"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/codeofconduct.json b/apps/app/src/jobs/seed/policies/codeofconduct.json index 9ae031c24e..694c2c0261 100644 --- a/apps/app/src/jobs/seed/policies/codeofconduct.json +++ b/apps/app/src/jobs/seed/policies/codeofconduct.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC1.1", "CC1.5"] + "controls": ["CC1.1", "CC6.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/confidentiality.json b/apps/app/src/jobs/seed/policies/confidentiality.json index 63719b4192..de4fce104b 100644 --- a/apps/app/src/jobs/seed/policies/confidentiality.json +++ b/apps/app/src/jobs/seed/policies/confidentiality.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC9.9", "CC8.1"] + "controls": ["CC9.9", "CC6.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/cyberrisk.json b/apps/app/src/jobs/seed/policies/cyberrisk.json index e6fb8168cb..a4e5eccf2b 100644 --- a/apps/app/src/jobs/seed/policies/cyberrisk.json +++ b/apps/app/src/jobs/seed/policies/cyberrisk.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC9.1", "CC8.1"] + "controls": ["CC1.1", "CC1.2", "CC1.3", "CC1.4", "CC1.5"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/datacenter.json b/apps/app/src/jobs/seed/policies/datacenter.json index e41467c409..0abd834ff1 100644 --- a/apps/app/src/jobs/seed/policies/datacenter.json +++ b/apps/app/src/jobs/seed/policies/datacenter.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC6.1", "CC6.2", "CC9.1"] + "controls": ["CC6.1", "CC6.2", "CC8.1", "CC7.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/dataclassification.json b/apps/app/src/jobs/seed/policies/dataclassification.json deleted file mode 100644 index 22c00b6fef..0000000000 --- a/apps/app/src/jobs/seed/policies/dataclassification.json +++ /dev/null @@ -1,164 +0,0 @@ -{ - "type": "doc", - "metadata": { - "controls": ["CC9.9", "CC8.1"] - }, - "content": [ - { - "type": "heading", - "attrs": { "level": 1 }, - "content": [{ "type": "text", "text": "Data Classification Policy" }] - }, - { - "type": "heading", - "attrs": { "level": 2 }, - "content": [{ "type": "text", "text": "Policy Information" }] - }, - { - "type": "table", - "content": [ - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } - ] - }, - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } - ] - } - ] - }, - { - "type": "heading", - "attrs": { "level": 2 }, - "content": [{ "type": "text", "text": "Purpose and Scope" }] - }, - { - "type": "orderedList", - "attrs": { "tight": true, "start": 1 }, - "content": [ - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to establish guidelines for classifying, labeling, and handling data within the organization to ensure appropriate protection and compliance with legal, regulatory, and contractual requirements." }] } - ] - }, - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, and third parties who access, handle, or manage the organization’s data." }] } - ] - }, - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "All data within the organization, including electronic and physical records, falls under the scope of this policy." }] } - ] - } - ] - }, - { - "type": "heading", - "attrs": { "level": 2 }, - "content": [{ "type": "text", "text": "Data Classification Levels" }] - }, - { - "type": "table", - "content": [ - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "Classification Level" }] }, - { "type": "tableCell", "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "Description" }] }, - { "type": "tableCell", "content": [{ "type": "text", "marks": [{ "type": "bold" }], "text": "Access Restrictions" }] } - ] - }, - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "text": "Public" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Information intended for public release that does not pose any risk to the organization if disclosed." }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Accessible to everyone." }] } - ] - }, - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "text": "Internal Use" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Non-sensitive business information intended for internal use only." }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Accessible to employees and authorized third parties." }] } - ] - }, - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "text": "Restricted" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Sensitive business information that could cause harm to the organization if disclosed." }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Accessible only to authorized personnel with a need-to-know basis." }] } - ] - }, - { - "type": "tableRow", - "content": [ - { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Highly sensitive information that could cause significant damage to the organization if disclosed." }] }, - { "type": "tableCell", "content": [{ "type": "text", "text": "Strictly limited to specific individuals and requires additional security measures." }] } - ] - } - ] - }, - { - "type": "heading", - "attrs": { "level": 2 }, - "content": [{ "type": "text", "text": "Data Handling Requirements" }] - }, - { - "type": "orderedList", - "attrs": { "tight": true, "start": 1 }, - "content": [ - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "Classified information must be labeled according to its classification level." }] } - ] - }, - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "Data must be protected in transit and at rest based on its classification." }] } - ] - }, - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "Access to classified information must be controlled based on the principle of least privilege." }] } - ] - }, - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "Confidential data must be encrypted and stored in secure locations." }] } - ] - }, - { - "type": "listItem", - "content": [ - { "type": "paragraph", "content": [{ "type": "text", "text": "Employees handling classified data must adhere to security and compliance guidelines." }] } - ] - } - ] - } - ] - } - \ No newline at end of file diff --git a/apps/app/src/jobs/seed/policies/riskassessment.json b/apps/app/src/jobs/seed/policies/riskassessment.json index 182473b981..64ed2fe330 100644 --- a/apps/app/src/jobs/seed/policies/riskassessment.json +++ b/apps/app/src/jobs/seed/policies/riskassessment.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC9.1", "CC8.1"] + "controls": ["CC3.2", "CC3.4", "CC8.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/softwaredevelopment.json b/apps/app/src/jobs/seed/policies/softwaredevelopment.json index 75881ea51d..2a22df0dd9 100644 --- a/apps/app/src/jobs/seed/policies/softwaredevelopment.json +++ b/apps/app/src/jobs/seed/policies/softwaredevelopment.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC6.2", "CC8.1", "CC9.1"] + "controls": ["CC6.2", "CC7.1", "CC7.2", "CC8.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/thirdparty.json b/apps/app/src/jobs/seed/policies/thirdparty.json index 17c3aad9dc..16e0c8a341 100644 --- a/apps/app/src/jobs/seed/policies/thirdparty.json +++ b/apps/app/src/jobs/seed/policies/thirdparty.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC8.1", "CC9.1"] + "controls": ["CC2.3", "CC7.3", "CC8.1"] }, "content": [ { diff --git a/apps/app/src/jobs/seed/policies/workstation.json b/apps/app/src/jobs/seed/policies/workstation.json index fb496980d0..d2954dcf86 100644 --- a/apps/app/src/jobs/seed/policies/workstation.json +++ b/apps/app/src/jobs/seed/policies/workstation.json @@ -1,7 +1,7 @@ { "type": "doc", "metadata": { - "controls": ["CC6.1", "CC6.2"] + "controls": ["CC6.2", "CC6.7", "CC7.2"] }, "content": [ { From d3456dd2dbd739a71ff4a7457d88eca9574ff5db Mon Sep 17 00:00:00 2001 From: Austin Songer Date: Thu, 13 Feb 2025 22:10:04 +0000 Subject: [PATCH 14/14] add Disaster Recovery Policy document with controls CC9.1 and CC8.1 Signed-off-by: Austin Songer --- .../jobs/seed/policies/disasterrecovery.json | 195 ++++++++++++++++++ 1 file changed, 195 insertions(+) create mode 100644 apps/app/src/jobs/seed/policies/disasterrecovery.json diff --git a/apps/app/src/jobs/seed/policies/disasterrecovery.json b/apps/app/src/jobs/seed/policies/disasterrecovery.json new file mode 100644 index 0000000000..ed634a9f9e --- /dev/null +++ b/apps/app/src/jobs/seed/policies/disasterrecovery.json @@ -0,0 +1,195 @@ +{ + "type": "doc", + "metadata": { + "controls": ["CC9.1", "CC8.1"] + }, + "content": [ + { + "type": "heading", + "attrs": { "level": 1 }, + "content": [{ "type": "text", "text": "Disaster Recovery Policy" }] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Policy Information" }] + }, + { + "type": "table", + "content": [ + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "Organization" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Last Review" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Review Frequency" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Approved By" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Classification" }] } + ] + }, + { + "type": "tableRow", + "content": [ + { "type": "tableCell", "content": [{ "type": "text", "text": "{{organization}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "{{date}}" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Annual" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Chief Information Security Officer" }] }, + { "type": "tableCell", "content": [{ "type": "text", "text": "Confidential" }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Purpose and Scope" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The purpose of this policy is to establish a structured approach for disaster recovery (DR) planning to ensure that critical business operations can be resumed in the event of a disruption." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "This policy applies to all employees, contractors, and third parties responsible for IT infrastructure, data, and business continuity planning." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The policy covers disaster recovery procedures for IT systems, applications, network infrastructure, and data." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Disaster Recovery Planning Requirements" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must maintain a Disaster Recovery Plan (DRP) that defines recovery objectives, responsibilities, and procedures to restore operations following a disaster." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The DRP must identify critical systems, applications, and personnel required for recovery." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) must be established and tested periodically." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Disaster recovery drills and tests must be conducted at least annually to ensure readiness." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Backup and Data Protection" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Critical business data must be backed up regularly and stored securely." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Backups must be encrypted and stored in geographically separate locations." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Backup restoration tests must be conducted periodically to verify data integrity and recovery procedures." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Incident Response and Communication" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must have an incident response plan outlining procedures for disaster response and business continuity activation." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "A designated Disaster Recovery Team (DRT) must oversee crisis management and ensure recovery measures are implemented." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Employees must be informed of emergency procedures, including alternative work arrangements if needed." }] } + ] + } + ] + }, + { + "type": "heading", + "attrs": { "level": 2 }, + "content": [{ "type": "text", "text": "Compliance and Review" }] + }, + { + "type": "orderedList", + "attrs": { "tight": true, "start": 1 }, + "content": [ + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The Disaster Recovery Policy must be reviewed annually and updated as necessary." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "The organization must ensure compliance with industry standards and regulatory requirements related to disaster recovery and business continuity." }] } + ] + }, + { + "type": "listItem", + "content": [ + { "type": "paragraph", "content": [{ "type": "text", "text": "Non-compliance with this policy may result in corrective actions, including training, enhanced security controls, or disciplinary measures." }] } + ] + } + ] + } + ] + } + \ No newline at end of file