Skip to content

Draft: Gong - Tech Stack - Add New System & System Onboarding

Kyle Smith requested to merge ks-add-gong-to-tech-stack into master

Tech Stack - Add New System & System Onboarding

Please do not merge before the Business Systems Analysts have reviewed and approved!

Questions? Ask in #tech-owners_tech-stack Slack channel.

Business/Technical System Owner or Delegate to Complete

  • Rename this MR's title to [System Name] - Tech Stack - Add New System & System Onboarding

General Tech Stack Entry Tasks

  1. Requisition Link (if an externally-developed System): Link
  2. Populate all data fields within the 'Changes' tab of this MR. More instructions are here.
  3. Check this box to indicate approval of the New System's Critical System Tier.
  4. Is this New System replacing an existing System in the Tech Stack?
    • Yes - Delete the existing System's entry from the Tech Stack within this MR. Next, create a Tech Stack Offboarding Issue. Offboarding Issue Link:
    • No

Access Tasks

  1. Create an Issue to add the Provisioner(s) of the New System to the appropriate Google/Slack/GitLab groups. Note: If the Provisioner(s) of this System is already part of the Provisioner groups, skip this step. Please replace the link placeholder below with N/A - Already in Provisioner groups.
    • Issue Link:
  2. Add the New System to one of two Offboarding templates below. More instructions are here.

System Onboarding Checklist

  1. Is the New System configured for Okta Single Sign On?
  2. Is encryption of data in-transit and data at-rest enabled for the New System?
    • Yes
    • No
  3. Do System administrators (GitLab Team Members) have access to system logs?
    • Yes
    • No
  4. Have all SOC 2 CUECs been reviewed and implemented (as applicable)?
    • Yes - Link to Comment in TPRM Assessment Report Issue indicating confirmation from Business Team:
    • No
    • N/A
  5. Please review the following items:

Privacy Team to Complete

If the New System contains Personal Data, has a Privacy Review been completed?:

  • If System contains Orange (internal only) / RED Personal Data:
    • Yes - Link a completed Privacy Review Issue, Coupa approval, or Zip approval.
    • No - Complete Privacy Review Issue
  • If System contains Yellow Personal Data (GitLab Team Member Names/Emails):
    • Yes - a Data Processing Agreement (DPA) was executed between GitLab and the Vendor.
    • No - a DPA is not in place. Privacy Team will be in contact about completing a DPA, which is required for this Tech Stack Addition.
  • If System contains only Green Data or contains no Personal Data, a Privacy Review is not required.

Security Logging Team to Complete

  • @gitlab-com/gl-security/security-operations/security-logging acknowledges the New System is appropriately logged.

Security Risk Team to Complete

  1. Answer Question 4. in 'System Onboarding Checklist' section above.
  2. Was a Technical Security Validation launched in response to the TPRM Assessment?
    • Yes - Link the TSV here and confirm all steps within the Observation Management section of the TSV have been completed, including acknowledgment of TSV findings by the Business Owner if findings were noted.
    • No - No further action needed.

Business Technology Team to Complete

  • To-do before merging -- (@marc_disabatino) is to ensure all sections/action items are completed.

/cc @gitlab-com/internal-audit @disla

Edited by Eugene McCrann

Merge request reports