sourcegraph / sourcegraph-public-snapshot

Code AI platform with Code Search & Cody
https://sourcegraph.com
Other
10.12k stars 1.29k forks source link

DevX SOC2 compliance items: Tracking issue #29724

Closed taylorsperry closed 2 years ago

taylorsperry commented 2 years ago

Plan

Tracking issue for outstanding SOC2 compliance work.

โžก๏ธ Because SoC2 first phase deadline is in two weeks, we need to move fast on this. Aim for simplicity. Seeking for feedback early from the SecTeam is the best way to proceed. We don't need everything to be perfect.

Tracking for our SOC2 documentation: https://sourcegraph.com/notebooks/Tm90ZWJvb2s6NjA=

Priorities

  1. 29763

  2. 29762

  3. 29766

  4. The others

Availability

If you have planned unavailability this iteration (e.g., vacation), you can note that here.

Tracked issues

@unassigned

Completed

@bobheadxi

Completed

@davejrt

Completed

@jhchabran

Completed

@taylorsperry

Completed

Legend

taylorsperry commented 2 years ago

I don't think these are all GN-105, are they?

bobheadxi commented 2 years ago

Many are part of RFC 568 which pertains to SOC 2, and from what I understand the rest are also all testing-process related which seems covered by GN-105?

Application and infrastructure changes are required to undergo functional, security, unit, integration, smoke, regression, and SAST testing prior to release to production.

Sorry if I got some wrong - please let me know which ones should be corrected/feel free to correct them directly!