Audit Policy | DefectDojo Trust Center

Audit Policy

1. Purpose

The purpose of this policy is to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the auditing of all systems, networks, and IT assets for which they are assigned ownership and maintenance.

2. Scope

Audit management as applied to information security and the confidentiality, integrity, and availability of company-owned, processed, stored, and transmitted information.

3. Compliance

3.1 Compliance Measurement

The Information Security Management team will verify compliance to this document through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the document owner.

3.2 Exceptions

Any exception to the policy must be reviewed and approved in advance by the Management Review Team.

3.3 Non-Compliance

Any DefectDojo Staff found to have violated this document may be subject to disciplinary action, up to and including termination of employment.

3.4 Continual Improvement

This document is updated and reviewed as part of the continual improvement and process.

4. Requirements

4.1 DefectDojo Staff Supporting Audits

4.2 Security Operations Team

The Security Operations Team will adhere to the following principles for performing audits:

4.2.1 Impact Minimization

4.2.2 Audit Scheduling

4.2.3 Audit Screening and Vetting

4.2.4 Audit Scope

4.2.5 Auditor Access

4.2.6 Confidential Information and Retention

4.2.7 Auditor Objectivity

4.2.8 Audit Documentation and Reporting

5. Relevant Documents