Skip to content
Logo

Security Policies and Procedures

Security SpecialistLegal & ComplianceOperations & StrategyHR

Authored by:

Patrick Collins
Patrick Collins
Cyfrin

🔑 Key Takeaway: External product reviews are stronger when policies for IR, access, change management, and training exist and match real practice—not only binder aspirational documents.

As part of the external security review, it could be beneficial to also review the internal security policies and procedures as well. Some of the things that could be relevant to review are:

  1. Ensure there is a developed and maintained plan for responding to security incidents.
  2. Ensure there are defined roles and responsibilities, and enforce the principle of least privilege.
  3. Ensure there are processes implemented for managing changes to the codebase and infrastructure.
  4. Ensure there are regular training sessions conducted for all team members on security best practices.
  5. Ensure adherence to any potentially relevant regulatory and industry standards for your project.

Further Reading