<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security &amp; IT Controls on DefectDojo Trust Center</title><link>/policies/security_it_controls/</link><description>Recent content in Security &amp; IT Controls on DefectDojo Trust Center</description><generator>Hugo</generator><language>en-US</language><copyright>Copyright (c) 2020-2024 Thulite</copyright><lastBuildDate>Thu, 08 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="/policies/security_it_controls/index.xml" rel="self" type="application/rss+xml"/><item><title>Anti Virus Policy</title><link>/policies/security_it_controls/defectdojo-anti-virus-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/security_it_controls/defectdojo-anti-virus-policy/</guid><description>&lt;h2 id="definitions"&gt;Definitions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Virus:&lt;/strong&gt; A program that attaches itself to an executable file or vulnerable application and delivers a payload ranging from annoying to extremely destructive. A file virus executes when an infected file is accessed. A macro virus infects executable code embedded in Microsoft Office programs that allow users to generate macros.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Trojan Horse:&lt;/strong&gt; Destructive programs, usually viruses or worms, hidden in an attractive or innocent-looking piece of software, such as a game or graphics program. Victims may receive a Trojan horse via email, removable media, or downloads from websites.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Worm:&lt;/strong&gt; A program that copies itself elsewhere in a computing system, either on the same computer or across networks. Worms may disrupt networks by overloading them. Unlike viruses, worms do not need to attach to files.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Spyware:&lt;/strong&gt; Programs that install and gather information from a computer without permission, reporting it to the creator or third parties.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Malware:&lt;/strong&gt; Short for malicious software; programs designed to damage or disrupt a system, including viruses, worms, and Trojan horses.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Adware:&lt;/strong&gt; Programs installed without user consent or bundled with software to display ads, often causing system slowness or errors.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Keyloggers:&lt;/strong&gt; Programs that capture keystrokes and may also record screen images, often sending data to a third party.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ransomware:&lt;/strong&gt; Malware that restricts user access to systems or files until a ransom is paid.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Server:&lt;/strong&gt; A computer program that provides services to other programs or devices. A computer running a server program is referred to as a server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Incident:&lt;/strong&gt; An assessed event of unauthorized entry or attack on an automated information system, including disruption, destruction, or alteration of system functions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;E-mail:&lt;/strong&gt; Electronic mail, consisting of messages sent over electronic media by a communications application.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Malware threats must be managed to minimize downtime on DefectDojo, Inc. systems and protect critical systems and member data. This policy is established to:&lt;/p&gt;</description></item><item><title>Cloud and Infrastructure Security Policy</title><link>/policies/security_it_controls/defectdojo-cloud-and-infrastructure-security-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/security_it_controls/defectdojo-cloud-and-infrastructure-security-policy/</guid><description>&lt;h2 id="1-purpose"&gt;1. Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this document is to ensure the security of DefectDojo cloud and infrastructure resources. In addition, it informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations with regards to the cloud and infrastructure security of all systems, networks, IT assets, and licensed software, owned, operated, or used by DefectDojo.&lt;/p&gt;</description></item><item><title>Information Security Policy</title><link>/policies/security_it_controls/defectdojo-information-security-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/security_it_controls/defectdojo-information-security-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this policy is to set out the information security policies that apply to DefectDojo to protect the confidentiality, integrity, and availability of data. Additionally, it informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the Information Security Policy of all systems, networks, IT assets, and licensed software owned, operated, or used by DefectDojo.&lt;/p&gt;</description></item><item><title>Key Management Policy</title><link>/policies/security_it_controls/defectdojo-key-management-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/security_it_controls/defectdojo-key-management-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this policy is to ensure the proper lifecycle management of encryption keys to protect the confidentiality and integrity of confidential information. Additionally, it informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the management of encryption keys across all systems, networks, IT assets, and licensed software owned, operated, or used by DefectDojo.&lt;/p&gt;</description></item><item><title>Physical and Environmental Security Policy</title><link>/policies/security_it_controls/defectdojo-physical-and-environmental-security-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/security_it_controls/defectdojo-physical-and-environmental-security-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This policy aims to prevent unauthorized physical access, damage, and interference to DefectDojo’s information and information processing facilities. It also informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding physical and environmental security.&lt;/p&gt;</description></item><item><title>Vulnerability Management Policy</title><link>/policies/security_it_controls/defectdojo-vulnerability-management-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/security_it_controls/defectdojo-vulnerability-management-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this policy is to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations with regards to the Vulnerability Management of all systems, networks, and IT assets for which they are assigned ownership and maintenance.&lt;/p&gt;</description></item></channel></rss>