Acceptable Use Policy | DefectDojo Trust Center

Acceptable Use Policy

1. Purpose

The purpose of this document is to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations with regards to the acceptable use of all systems, networks, IT assets, and licensed software, owned, operated, or used by DefectDojo.

2. Scope

This policy applies to all DefectDojo Staff and any external parties who have access to DefectDojo equipment, systems, or networks.

3. Compliance

3.1 Compliance Measurement

The Information Security Management team will verify compliance to this document through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the document owner.

3.2 Exceptions

Any exception to the policy must be reviewed and approved in advance by the Management Review Team.

3.3 Non-Compliance

Any DefectDojo Staff found to have violated this document may be subject to disciplinary action, up to and including termination of employment.

3.4 Continual Improvement

This document is updated and reviewed as part of the continual improvement and process.

4. Requirements

4.1 Use of Corporate Email

DefectDojo Staff must only use a DefectDojo-provided email to conduct any business operations and activities, including but not limited to any communication, automation, or registration activities.

DefectDojo Staff must only use their DefectDojo-provided email for DefectDojo-related business activities and not personal use.

4.2 Secure Authentication and Protection of Credentials

DefectDojo Staff must protect the authentication information used to access DefectDojo computer systems, IT assets, licensed software, and networks. At the minimum, DefectDojo Staff must:

4.3 Maintenance of Device Security

DefectDojo Staff must keep systems, networks, IT assets, and licensed software owned, operated, or used by DefectDojo up to date and never attempt to circumvent any security control or setting, such as automatic system patching and maintenance, mobile device management software, malware protection software, logging and monitoring, and others.

4.4 Training

DefectDojo Staff must complete all mandatory training assigned to them upon hire and throughout their employment. DefectDojo Staff will acknowledge their understanding of the content of any such training assigned to them.

4.5 Notifying Security Operations in Cases of Suspected Security Incidents

DefectDojo Staff must immediately notify DefectDojo Security Operations team if they suspect or have identified that a security incident or a data breach has taken place. DefectDojo Staff will follow the guidelines provided accordingly in the Incident Response Policy.

4.6 Handling and Disposal of Data

DefectDojo Staff must handle data in accordance with its classification, as described in the Data Classification Policy.

DefectDojo Staff must retain data only if it is a business necessity. All data that is no longer needed must be securely disposed of, as described in the Data Retention Policy.

DefectDojo retains the right to delete or render inaccessible any data stored upon any DefectDojo owned or controlled system or device.

4.7 Examples of Unauthorized Use

Unauthorized use of DefectDojo systems, networks, IT assets, and licensed software is prohibited. DefectDojo will investigate incidents involving such violations and may involve and will cooperate with law enforcement if a criminal offense is suspected.

The following is an indicative and not exhaustive list, provided with examples of such unauthorized use:

4.7.1 Prohibition of Unlawful Activity

Anyone to whom this Policy applies must not undertake or accomplish any action that is illegal, unlawful, or otherwise constitutes a criminal, civil or administrative violation of any applicable local, state, provincial, federal, national, or international law, treaty, court order, ordinance, regulation, or administrative rule.

4.7.2 Conduct and Information Prohibitions

Anyone to whom this Policy applies must not:

4.7.3 Technical Prohibitions

Anyone to whom this Policy applies must not:

5. Relevant Documents