organizational
Confidentiality agreements signed
All employees and contractors sign NDAs upon hire.
PassingLow RiskSemi-Automated
Owner
Security Team
Last Tested
10/6/2025
Test Frequency
Continuous
Maturity Level
Level 4 / 5
Framework Mappings
Evidence (9)
Vulnerability scanning is enabled (GitHub)
This test verifies that vulnerability scanning (via Dependabot) is enabled for your GitHub repositories, allowing you to identify and manage software vulnerabilities effectively.
VULNERABILITY MANAGEMENT•TEST
Information Security Roles and Responsibilities
This policy and associated guidance establish the roles and responsibilities within the company, which is critical for effective communication of information security policies and standards.
Uncategorized•POLICY
Cryptography Policy
To ensure proper and effective use of cryptography to protect the confidentiality, authenticity and/or integrity of information. This policy establishes requirements for the use and protection of cryptographic keys throughout their entire lifecycle.
Uncategorized•POLICY
Code of Conduct
Develops and maintains a standard of conduct that is acceptable to the company and its employees, customers, and vendors.
Uncategorized•POLICY
Critical vulnerabilities identified in packages are addressed (GitHub Repo)
This test ensures that all critical severity vulnerabilities identified by GitHub's Dependabot in your repositories are addressed and resolved.
VULNERABILITY MANAGEMENT•TEST
High vulnerabilities identified in packages are addressed (GitHub Repo)
This test ensures that all high severity vulnerabilities identified by GitHub's Dependabot in your repositories are addressed and resolved.
VULNERABILITY MANAGEMENT•TEST
Low vulnerabilities identified in packages are addressed (GitHub Repo)
This test ensures that all low severity vulnerabilities identified by GitHub's Dependabot in your repositories are addressed and resolved.
VULNERABILITY MANAGEMENT•TEST
Medium vulnerabilities identified in packages are addressed (GitHub Repo)
This test ensures that all medium severity vulnerabilities identified by GitHub's Dependabot in your repositories are addressed and resolved.
VULNERABILITY MANAGEMENT•TEST
Security awareness training selected
This test checks whether your organization has selected a general security awareness training program. Choosing a training program is the first step to ensure employees receive education on fundamental security best practices.
EMPLOYEES•TEST
Related Policies
Control Information
- Control ID
- confidentiality-agreements-signed
- Category
- ORGANIZATIONAL
- Family
- organizational
- Last Updated
- 10/6/2025