Policies
No policies match the current filters.
Classifying and Securing Data Work Instruction
SNow
State: publishedValid From: 2021-04-21 12:10:23Valid To: 2030-12-30 22:59:59
Classifying and Securing Data Work Instruction
Control Objectives (1)
Guideline - Encryption of Emails
SNow
State: publishedValid From: 2020-02-03 12:59:31Valid To: 2030-12-30 22:59:59
Guideline - Encryption of Emails
Lost and Stolen Mobile Device Work Instruction
SNow
State: publishedValid From: 2017-11-08 13:09:40Valid To: 2030-12-30 22:59:59
Lost and Stolen Mobile Device Work Instruction
MSB for Open Virtualization Appliances (OVAs) and Non-Standard Systems
SNow
State: publishedValid From: 2018-06-06 12:07:18Valid To: 2030-12-30 22:59:59
MSB for Open Virtualization Appliances (OVAs) and Non-Standard Systems
MSB for Web Applications
SNow
State: publishedValid From: 2017-10-06 12:06:48Valid To: 2030-12-30 22:59:59
MSB for Web Applications
Control Objectives (1)
Roche Certificate Policy
SNow
State: publishedValid From: 2020-06-16 11:54:33Valid To: 2030-12-29 23:00:00
Roche Certificate Policy
Roche Cloud Security Directive
SNow
State: publishedValid From: 2021-04-21 11:50:05Valid To: 2030-12-29 23:00:00
Roche Cloud Security Directive
Roche Directive on Classifying of Restricted Software and Services
SNow
State: publishedValid From: 2014-12-11 12:49:15Valid To: 2030-12-29 23:00:00
Roche Directive on Classifying of Restricted Software and Services
Roche Directive on Generic Identities
SNow
State: publishedValid From: 2019-05-22 11:53:49Valid To: 2030-12-29 23:00:00
Roche Directive on Generic Identities
Control Objectives (1)
Roche Directive on Secure Management of external Domain Names
SNow
State: publishedValid From: 2020-08-12 11:51:04Valid To: 2030-12-29 23:00:00
Roche Directive on Secure Management of external Domain Names
Roche Informatics Directive Continutiy Framework
SNow
State: publishedValid From: 2022-10-11 11:55:23Valid To: 2030-12-29 23:00:00
Roche Informatics Directive Continutiy Framework
Roche Informatics Policy for Continuity
SNow
State: publishedValid From: 2022-10-11 11:58:44Valid To: 2030-12-29 23:00:00
Roche Informatics Policy for Continuity
Roche Minimum Security Baseline (MSB) Security Standard
SNow
State: publishedValid From: 2019-05-22 11:52:53Valid To: 2030-12-30 22:59:59
Roche Minimum Security Baseline (MSB) Security Standard
Roche Network Security Standard
SNow
State: publishedValid From: 2017-11-29 13:03:02Valid To: 2030-12-29 23:00:00
Roche Network Security Standard
Roche Outsourced Delivery Center (ODC) Standard
SNow
State: draftValid From: 2020-04-01 11:46:09Valid To: 2030-12-29 23:00:00
Roche Outsourced Delivery Center (ODC) Standard
Control Objectives (9)
- Each ODC Engagement has a completed ODC Screening Assessment
- Each ODC Engagement has an ODC Manager assigned
- Each Outsorced Delivery Center has an ODC Manual in place
- Ensure vendor has an ODC Impact Assessment in complete state...
- ODC has formally documented Business Continuity and Disaster...
- Vendor Security Assessment
- Vendor has Cyber risk insurance which covers Data Breaches a...
- Vendor has a formal onboarding and offboarding process for e...
- Vendor has an industry recognized security certification fro...
Roche Password Management Standard
SNow
State: publishedValid From: 2019-07-04 11:56:00Valid To: 2030-12-29 23:00:00
Roche Password Management Standard
Roche Privileged Access Directive
SNow
State: publishedValid From: 2021-07-13 12:08:38Valid To: 2030-12-29 23:00:00
Roche Privileged Access Directive
Roche Security Patch Management Standard
SNow
State: publishedValid From: 2019-08-12 12:00:58Valid To: 2030-12-29 23:00:00
Roche Security Patch Management Standard
Control Objectives (2)
Roche Security Penetration Test Process
SNow
State: publishedValid From: 2021-04-28 12:04:28Valid To: 2030-12-30 22:59:59
Roche Security Penetration Test Process
Control Objectives (1)
Roche Software RoBot Security Standard
SNow
State: publishedValid From: 2019-07-05 11:51:52Valid To: 2030-12-29 23:00:00
Roche Software RoBot Security Standard
Secure Development of Web Applications
SNow
State: publishedValid From: 2014-10-28 13:06:14Valid To: 2030-12-30 22:59:59
Secure Development of Web Applications
Security Exception Management Process SOP
SNow
State: publishedValid From: 2020-05-07 12:03:52Valid To: 2030-12-30 22:59:59
Security Exception Management Process SOP
Security Exception Work Instruction
SNow
State: publishedValid From: 2017-11-07 13:07:56Valid To: 2030-12-30 22:59:59
Security Exception Work Instruction
Security Guidelines on Usage of Personal Devices
SNow
State: publishedValid From: 2013-12-18 12:56:59Valid To: 2030-12-30 22:59:59
Security Guidelines on Usage of Personal Devices
Control Objectives (1)
Security Patch Management SOP
SNow
State: publishedValid From: 2020-02-26 13:00:12Valid To: 2030-12-30 22:59:59
Security Patch Management SOP
Third Party Security Assessments and Audits
SNow
State: publishedValid From: 2019-09-14 11:57:45Valid To: 2030-12-30 22:59:59
This document defines standard operating procedures for the processing and management of Third Party Security Assessments and Audits focusing on information security, data privacy and compliance risks (hereinafter referred to Vendor Security Assessment, VSA). The Third Party Security Assessments and
Control Objectives (1)