Skip to content

Telesign - Tech Stack - Add New System + Alphabetize 'Teleport'

Tech Stack - Add New System & System Onboarding

Please do not merge before the Business Systems Analysts have reviewed and approved!

Questions? Ask in #tech-owners_tech-stack Slack channel.

Business/Technical System Owner or Delegate to Complete

General Tech Stack Entry Tasks

  1. Rename this MR's title to [System Name] - Tech Stack - Add New System & System Onboarding
  2. Requisition Link (if an externally-developed System): https://gitlab.ziphq.com/request/51f98cf4-fe67-446c-aa26-bd1714516271
  3. Populate all data fields using the Web IDE. More instructions are here.
  4. Is this New System replacing an existing System in the Tech Stack?
    • Yes - Delete the existing System's entry from the Tech Stack in this MR using the Web IDE. Next, create a Tech Stack Offboarding Issue. Offboarding Issue Link:
    • No

Access Tasks

  1. Add the New System to one of two Offboarding templates below. More instructions are here.

System Onboarding Checklist

Each checklist item below should be addressed before this MR can be merged. Reach out to Security Risk in the #tech-owners_tech-stack Slack channel for help.

  1. The New System is configured for Okta Single Sign On.
  2. Encryption of data in-transit and data at-rest are enabled for the New System.
  3. GitLab's implementation of the New System has audit logging enabled and documented.
  4. All SOC 2 CUECs have been reviewed and implemented (as applicable). Note: Security Risk will address this item.
    • Yes - Link to Comment in TPRM Assessment Report Issue indicating confirmation from Business Team:
    • N/A
      • Rationale (Populate): ISO 27001 Cert. was provided.
    • Please review the following items:

Privacy Team to Complete

If the New System contains Personal Data, has a Privacy Review been completed?:

  • If System contains Orange (internal only) / RED Personal Data:
    • Yes - Link a completed Privacy Review Issue, Coupa approval, or Zip approval.
    • No - Complete Privacy Review Issue
  • If System contains Yellow Personal Data (GitLab Team Member Names/Emails):
    • Yes - a Data Processing Agreement (DPA) was executed between GitLab and the Vendor.
    • No - a DPA is not in place. Privacy Team will be in contact about completing a DPA, which is required for this Tech Stack Addition.
  • If System contains only Green Data or contains no Personal Data, a Privacy Review is not required.

Security Risk Team to Complete

  1. Check this box to indicate approval of the New System's Critical System Tier.
  2. Answer Question 4. in 'System Onboarding Checklist' section above.
    • Was a Technical Security Validation launched in response to the TPRM Assessment?
      • Yes - Link the TSV here and confirm all steps within the Observation Management section of the TSV have been completed, including acknowledgment of TSV findings by the Business Owner if findings were noted.
      • No - No further action needed.

Business Technology Team to Complete

  • To-do before merging -- (@marc_disabatino) is to ensure all sections/action items are completed.

/cc @gitlab-com/internal-audit @disla

Edited by Nirmal Devarajan

Merge request reports

Loading