graphgrc

Engineering Security Policy

Security requirements specific to software engineers and developers.

Purpose

This policy establishes secure development practices to prevent security vulnerabilities in code and infrastructure. Applies in addition to the baseline-security-policy.md.

Scope

Applies to all engineers, including software engineers, SREs, DevOps engineers, and contractors writing code or managing infrastructure.

Secure Coding

Requirements

Responsibilities

Secrets Management

Requirements

Responsibilities

Access Control

Requirements

Responsibilities

Code Review

Requirements

Responsibilities

Development Environments

Requirements

Responsibilities

Dependency Management

Requirements

Responsibilities

Infrastructure as Code

Requirements

Responsibilities

Testing

Requirements

Responsibilities

Deployment Security

Requirements

Responsibilities

Incident Response

Requirements

Responsibilities

Third-Party Integrations

Requirements

Responsibilities

Personal Projects and Open Source

Requirements

Responsibilities

Exceptions

Exceptions to this policy require written approval from Security Team Lead with business justification. Approved exceptions documented and reviewed quarterly.

Training

References

Control Mapping


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.