Skip to content

Commit

Permalink
GITBOOK-870: Security policy update / added new policies and directed…
Browse files Browse the repository at this point in the history
… them to Internal Handbook
  • Loading branch information
mayarafsantos authored and gitbook-bot committed Aug 24, 2023
1 parent bc50b23 commit 4ea81ab
Show file tree
Hide file tree
Showing 18 changed files with 267 additions and 154 deletions.
18 changes: 12 additions & 6 deletions SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,24 +150,30 @@
* [🔐 Security](departments-operations/security/README.md)
* [Roles and Responsibilities](departments-operations/security/roles-and-responsibilities.md)
* [Security Policy](departments-operations/security/security-policy.md)
* [Internal Controls Policy](departments-and-operations/security/security-policy/internal-controls-policy.md)
* [Assets Management](departments-operations/security/security-policy/assets-management.md)
* [Data Classification and Management](departments-operations/security/security-policy/data-classification-and-management/README.md)
* [Google docs data classification](departments-operations/security/security-policy/data-classification-and-management/google-docs-data-classification.md)
* [Remote work](departments-operations/security/security-policy/remote-work.md)
* [Cryptography and Key management](departments-operations/security/security-policy/cryptography-and-key-management.md)
* [Authentication and Password policies](departments-operations/security/security-policy/authentication-and-password-policies.md)
* [Access Control](departments-operations/security/security-policy/access-control.md)
* [Network Security](departments-and-operations/security/security-policy/network-security.md)
* [Remote work](departments-operations/security/security-policy/remote-work.md)
* [Cryptography and Key management](departments-operations/security/security-policy/cryptography-and-key-management.md)
* [Data Classification and Management](departments-operations/security/security-policy/data-classification-and-management/README.md)
* [Google docs data classification](departments-operations/security/security-policy/data-classification-and-management/google-docs-data-classification.md)
* [Data Retention and Disposal](departments-and-operations/security/security-policy/data-classification-and-management/data-retention-and-disposal.md)
* [Secure Data Transfer](departments-and-operations/security/security-policy/secure-data-transfer.md)
* [Secure Development](departments-and-operations/security/security-policy/secure-development.md)
* [Changes Management](departments-operations/security/security-policy/changes-management/README.md)
* [Rocket.Chat code](departments-operations/security/security-policy/changes-management/rocket.chat-code/README.md)
* [Delegation letter](departments-operations/security/security-policy/changes-management/rocket.chat-code/delegation-letter.md)
* [Supplier Relationship](departments-operations/security/security-policy/supplier-relationship.md)
* [Vulnerability and Patch Management](departments-and-operations/security/security-policy/vulnerability-and-patch-management.md)
* [Business Continuity and Disaster Recovery](departments-operations/security/security-policy/business-continuity-and-disaster-recovery.md)
* [Supplier Relationship](departments-operations/security/security-policy/supplier-relationship.md)
* [Awareness and Training](departments-operations/security/security-policy/awareness-and-training.md)
* [Playbooks](departments-operations/security/playbooks/README.md)
* [Vulnerability Management Process](departments-operations/security/playbooks/vulnerability-management-process.md)
* [Vulnerability Reports & Disclosure](departments-operations/security/playbooks/vulnerability-reports-and-disclosure.md)
* [Security Logs ingestion and review](departments-operations/security/playbooks/security-logs-ingestion-and-review.md)
* [Alerts and Incident Management](departments-operations/security/playbooks/alerts-and-incident-management.md)
* [Vulnerability Reports & Disclosure](departments-operations/security/playbooks/vulnerability-reports-and-disclosure.md)
* [Pentest](departments-operations/security/playbooks/pentest.md)
* [Tasks & Project Management](departments-operations/security/playbooks/tasks-and-project-management.md)
* [Code Analysis](departments-operations/security/playbooks/code-analysis.md)
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
description: This policy applies to all employees and contractors.
---

# Data Retention and Disposal

## Purpose

The purpose of this Data Retention Policy is to establish guidelines for the appropriate management of data throughout its lifecycle. This policy aims to ensure compliance with relevant regulations and protect the privacy and security of data.

## Policy

[Data retention and disposal policy](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/data-classification-and-management/data-retention-and-disposal) is available to all employees and contractors within our internal handbook[.](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/data-classification-and-management/data-retention-and-disposal) 

##
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
description: This policy applies to all employees and contractors.
---

# Internal Controls Policy

## Purpose

The objective of our internal control policy is to establish and maintain effective information security controls that safeguard the confidentiality, integrity, and availability of Rocket.Chat’s assets and operations.

## Policy

[Internal Controls policy](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/internal-controls-policy) is available to all employees and contractors within our internal handbook.
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
description: Applicable to all employees and contractors.
---

# Network Security

## Purpose

The purpose of the network security policy is to establish guidelines and responsibilities to ensure the security and integrity of the organization's network infrastructure and data. It aims to protect sensitive information, prevent unauthorized access, mitigate security risks, and maintain compliance with relevant regulations.

## Policy

[Network security policy](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/network-security) is available to all employees and contractors within our internal handbook.



Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
description: This policy applies to all employees and contractors.
---

# Secure Data Transfer

## Purpose 

The purpose of Secure Data transfer policy is to establish guidelines and procedures for the secure transfer of sensitive data, both externally and internationally. It aims to protect the confidentiality, integrity, and availability of the organization's information assets during data transfers, while ensuring compliance with applicable laws, regulations, and contractual obligations.

## Policy

[Secure Data Transfer policy](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/secure-data-transfer)
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
description: >-
This policy applies to employees, contractors, and third-party vendors engaged
in software development activities within Rocket.Chat.
---

# Secure Development

## Purpose

The purpose of the secure development policy is to ensure that our software development processes prioritize security and incorporate robust security measures at every stage. This policy aims to protect our software applications, sensitive data, and customer information from unauthorized access, data breaches, and other security threats. By following this policy, we aim to deliver secure and reliable software solutions to our clients, comply with relevant regulations, and maintain the trust of our customers.

## Policy

[Secure Development Policy](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/secure-development)

\


Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# Vulnerability and Patch Management

## Purpose

The policy outlines the procedures for detecting, assessing vulnerabilities, and applying patches in software applications and infrastructure components used by our company. The primary objective is to enhance security by proactively identifying vulnerabilities and addressing them in a timely manner.

## Policy

Available at this [link](https://app.gitbook.com/o/-M41dOPtnjO7qK6KCyrt/s/-M7iRWz196Rdn-5pW5QY/\~/changes/1876/security/security-policies/security-policy/vulnerability-and-patch-management).  
Original file line number Diff line number Diff line change
Expand Up @@ -76,18 +76,7 @@ QA: QA Engineers are responsible for testing if the solution has fixed the vulne



| Week | Frontend | Backend |
| ----------- | ----------------- | ---------------- |
| 14-Nov-2022 | Tiago Evangelista | Luciano Pierdona |
| 21-Nov-2022 | Tiago Evangelista | Luciano Pierdona |
| 28-Nov-2022 | Tiago Evangelista | David Alen |
| 5-Dec-2022 | Tiago Evangelista | David Alen |
| 12-Dec-2022 | Yash Rajpal | David Alen |
| 19-Dec-2022 | Julia Forresti | David Alen |
| 26-Dec-2022 | Holidays | Holidays |
| 2-Jan-2023 | Pedro Rorato | Matheus Barbosa |
| 9-Jan-2023 | Pedro Rorato | Matheus Barbosa |
| 22-Feb-2023 | Gabriel Henriques | Rafael Tapia |
<table><thead><tr><th width="217.33333333333334">Week</th><th>Frontend</th><th>Backend</th></tr></thead><tbody><tr><td>14-Nov-2022</td><td>Tiago Evangelista</td><td>Luciano Pierdona</td></tr><tr><td>21-Nov-2022</td><td>Tiago Evangelista</td><td>Luciano Pierdona</td></tr><tr><td>28-Nov-2022</td><td>Tiago Evangelista</td><td>David Alen</td></tr><tr><td>5-Dec-2022</td><td>Tiago Evangelista</td><td>David Alen</td></tr><tr><td>12-Dec-2022</td><td>Yash Rajpal</td><td>David Alen</td></tr><tr><td>19-Dec-2022</td><td>Julia Forresti</td><td>David Alen</td></tr><tr><td>26-Dec-2022</td><td>Holidays</td><td>Holidays</td></tr><tr><td>2-Jan-2023</td><td>Pedro Rorato</td><td>Matheus Barbosa</td></tr><tr><td>9-Jan-2023</td><td>Pedro Rorato</td><td>Matheus Barbosa</td></tr><tr><td>22-Feb-2023</td><td>Gabriel Henriques</td><td>Rafael Tapia</td></tr></tbody></table>

\

Expand Down
Loading

0 comments on commit 4ea81ab

Please sign in to comment.