Physical and Environmental Security Policy | DefectDojo Trust Center

Physical and Environmental Security Policy

Purpose

This policy aims to prevent unauthorized physical access, damage, and interference to DefectDojo’s information and information processing facilities. It also informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding physical and environmental security.

Scope

Covers physical and environmental security as applied to information security and the confidentiality, integrity, and availability of company-owned, processed, stored, and transmitted information.

Compliance

Compliance Measurement

The Information Security Management team verifies compliance through business tool reports, internal and external audits, and feedback to the document owner.

Exceptions

Exceptions must be reviewed and approved in advance by the Management Review Team.

Non-Compliance

Violation of this policy may result in disciplinary action, up to and including termination.

Continual Improvement

The document is updated and reviewed as part of continual improvement.

Requirements

Principle

Physical and environmental security aims to exceed Health and Safety regulations while protecting sensitive physical assets based on risk.

Roles and Responsibilities

DefectDojo Staff

General Physical Security Requirements
Clear Desk/Clear Screen Requirements

Security and Technology Services

General Physical Security
Employee Access
Secure Areas
Visitor Access
Delivery and Loading Areas
Network Access Control
Cabling Security
Equipment Security

Relevant Documents