Information Security Policy | DefectDojo Trust Center

Information Security Policy

Purpose

The purpose of this policy is to set out the information security policies that apply to DefectDojo to protect the confidentiality, integrity, and availability of data. Additionally, it informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the Information Security Policy of all systems, networks, IT assets, and licensed software owned, operated, or used by DefectDojo.

Scope

Risk and risk management as applied to information security and the confidentiality, integrity, and availability of company-owned, processed, stored, and transmitted information.

Compliance

Compliance Measurement

The Information Security Management team will verify compliance to this document through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the document owner.

Exceptions

Any exception to this document must be reviewed and approved in advance by the Management Review Team.

Non-Compliance

Any DefectDojo Staff found to have violated this document may be subject to disciplinary action, up to and including termination of employment.

Continual Improvement

This document is updated and reviewed as part of the continual improvement process.

Requirements

Principle

Information security is managed based on risk, legal and regulatory requirements, and business needs.

Chief Executive’s Statement of Commitment

DefectDojo’s information processing is fundamental to the company’s success, and the protection and security of that information is a board-level priority. We take our obligations under regulatory (e.g., GDPR, Data Protection Act 2018) and industry best practice bodies (e.g., NIST, CSA, OWASP) seriously, whether employee information or customer information. Resources are provided to develop, implement, and continually improve the information security management system appropriate to our business.

Introduction

Information security protects the information entrusted to us. Errors in information security can have significant adverse impacts on employees, customers, reputation, and finances.

By maintaining an effective information security management system, DefectDojo can:

Information Security Defined

Information Security Objectives

Information Security Policy Framework

The information security management system is built upon a policy framework that includes the following policies:

Information Security Roles and Responsibilities

Information security is the responsibility of everyone. All staff must understand and adhere to policies, follow processes, and report suspected or actual breaches. Specific roles and responsibilities for managing the information security system are documented in the Security Operations wiki on Confluence.

Monitoring

Compliance with information security policies and procedures is monitored via the Management Review Team, together with independent reviews by both internal and external audits periodically.

Legal and Regulatory Obligations

DefectDojo maintains legal and regulatory obligations through:

Training and Awareness

Relevant Documents