Access Control Policy | DefectDojo Trust Center

Access Control Policy

1. Purpose

The purpose of this policy is to ensure the appropriate access to the correct information and resources is granted only for authorized users. In addition, to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations with regards to the User Access of all systems, networks, and IT assets, and licensed software owned, operated, or used by DefectDojo.

2. Scope

Access management to resources and information as applied to information security and the confidentiality, integrity, and availability of company-owned, processed, stored, and transmitted information.

3. Compliance

3.1 Compliance Measurement

The Information Security Management team will verify compliance to this document through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the document owner.

3.2 Exceptions

Any exception to this document must be reviewed and approved in advance by the Management Review Team.

3.3 Non-Compliance

Any DefectDojo Staff found to have violated this document may be subject to disciplinary action, up to and including termination of employment. In addition, systems and accounts that are found to violate this policy may be removed from the DefectDojo network, disabled, or suspended as appropriate, until such systems and accounts can comply with this policy.

3.4 Continual Improvement

This document is updated and reviewed as part of the continual improvement and process.

4. Requirements

4.1 Principle

Access control is granted on the principle of least privilege. Users are only provided access to the information they require to perform their tasks and role.

4.2 Confidentiality Agreements

All DefectDojo Staff who are given access to confidential information should sign a confidentiality or non-disclosure agreement prior to being given access to information processing facilities.

4.3 Role-Based Access

Access to systems is based on specific roles. Access is granted automatically based on the DefectDojo Staff member’s position in a particular department when a defined System for Cross-domain Identity Management (SCIM) is available and implemented. Manual access is granted by the System Owner or Data Custodian, and formally approved.

4.4 Unique Identifier

All users are assigned a unique username or identifier on the principle of one user ID to ensure individual accountability. Usernames and identifiers are not shared between users. If there is a valid and DefectDojo-approved need for a shared account, individual attribution to a specific user must be possible when a shared account is in use.

4.5 Authentication Before Access

Users are identified and authenticated before gaining access to systems, services, or information.

4.6 Access Rights Review

4.7 Privileged and Administrative Accounts

4.8 Multi-Factor Authentication

4.9 User Account Provisioning

4.10 Leavers

4.11 Authentication

4.12 Remote Access

4.13 Third-Party Remote Access

4.14 Account Suspension and Deletion after Termination

All accounts are suspended for 30 days after termination and then deleted, unless there is a legal hold requirement. This includes suspending and then deleting all regular, privileged, and third-party access accounts.

4.15 Monitoring and Reporting

Access to systems is monitored and reported, and actions that directly or indirectly affect or could affect the confidentiality, integrity, or availability of data are managed via the Incident Management process.

5. Relevant Documents