Artifacts: Information Security
No artifacts match the current filters.
Access Review Evidence
Information Security
ID: A005
Documented evidence of the user access review outcome for end-users and IT technical personnel, covering role appropriateness, training completion, inactive accounts, and corrective actions taken.
Source Documents (1)
Roles (2)
Information Security Policy
Information Security
ID: A090
Organizational policy defining information security requirements, controls, and standards to protect information assets and ensure confidentiality, integrity, and availability across Informatics systems.
Source Documents (1)
Password Escrow SOP
Information Security
ID: A109
A Standard Operating Procedure that defines the rules, rationale, and procedures for a specific password escrow use case. Required before any password escrow arrangement can be established.
Source Documents (1)
Processes (1)
Roche Password Dictionary
Information Security
ID: A141
A curated dictionary of prohibited passwords used to enforce password quality. Passwords must not match entries in this dictionary or appear in publicly available lists of breached passwords, optionally enforced via a Bloom filter.
Source Documents (1)
Processes (1)
Roles (1)
Security Exception Request
Information Security
ID: A145
A formal request for exception from the password requirements defined in the Password Management Standard. Handled through the Roche Information Security Risk Management Issues and Exception Process.
Source Documents (1)