Skip to content

Commit a2c33fc

Browse files
author
CvH
committed
Merge branch 'security' of https://github.com/0xPolygon/polygon-docs into security
2 parents e772b46 + f1d646b commit a2c33fc

File tree

2 files changed

+8
-8
lines changed

2 files changed

+8
-8
lines changed

docs/security/hr.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
Polygon supports onboarding and offboarding employees by following a process that begins with each employee receiving a preconfigured laptop that auto enrolls in one of our Mobile Device Management (MDM) systems. MDM supports control of application usage and enforces security policy requirements on approved operating system versions and patch requirements. User access to shared services and Polygon approved SaaS tools is secured by providing the least amount of privileges required for an employee to perform their tasks. Privileges are role based and given to each employee based on the functional team they are assigned to.
22

3-
Polygon uses single sign-on technologies to automate the administration of user access and permissions across all of our SaaS tools. Automating the provisioning and removal of users' access privileges limits the risk of human error and supports efficient auditing procedures.
3+
Polygon uses single sign-on technologies to automate the administration of user access and permissions across all its SaaS tools. Automating the provisioning and removal of users' access privileges limits the risk of human error and supports efficient auditing procedures.
44

55
When an employee exits the company, HR changes their status in our HRIS system, automatically removing their access to our SSO integrated SaaS platforms, and IT is immediately notified to initiate the wipe and recovery of their corporate system.
66

77
## Security awareness training
88

9-
Polygon utilizes a SaaS platform to provide an integrated approach to email and security awareness training for all of our employees. All employees are required to pass the training during their first weeks of employment. The key features of the platform are:
9+
Polygon uses a SaaS platform to provide an integrated approach to email and security awareness training for all of our employees. All employees are required to pass the training during their first weeks of employment. The key features of the platform are:
1010

11-
- Industry-specific modules: Reinforce critical concepts mapped to key industry standards and security frameworks, including ISO, NIST, PCI DSS, GDPR, and HIPAA
12-
- Real-world assessment: Safely test employees on real-world threats with de-weaponized phishing attacks
13-
- Comprehensive reporting: Track primary indicators of risk across the awareness training platform and take remedial action with easily discernible user risk scores
14-
- Integrated risk insight: Leverage real-world click behavior to identify high risk users
15-
- Effortless administration: 12-month programs with rapid deployment
11+
- Industry-specific modules: Reinforce critical concepts mapped to key industry standards and security frameworks, including ISO, NIST, PCI DSS, GDPR, and HIPAA.
12+
- Real-world assessment: Safely test employees on real-world threats with de-weaponized phishing attacks.
13+
- Comprehensive reporting: Track primary indicators of risk across the awareness training platform and take remedial action with easily discernible user risk scores.
14+
- Integrated risk insight: Leverage real-world click behavior to identify high risk users.
15+
- Effortless administration: 12-month programs with rapid deployment.

docs/security/infrastructure.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
## Polygon bridge security
22

3-
Polygon develops and maintains bridges to transfer assets to-and-from the Ethereum blockchain for both the Polygon PoS network and Polygon zkEVM scaling solution. These bridges implement a lock-and-mint architecture which results in assets being controlled (locked) by the bridge smart contract implementations. As the aggregate value of locked assets on Polygon bridges is significant, we apply a corresponding focus on bridge security. Much of the security efforts documented here are rigorously applied to bridge security, including risk management, secure software development practices, auditing, vulnerability management, CI/CI and bug bounties. We leverate dedicated on-chain bridge monitoring.
3+
Polygon develops and maintains bridges to transfer assets to-and-from the Ethereum blockchain for both the Polygon PoS network and Polygon zkEVM scaling solution. These bridges implement a lock-and-mint architecture which results in assets being controlled (locked) by the bridge smart contract implementations. As the aggregate value of locked assets on Polygon bridges is significant, we apply a corresponding focus on bridge security. Much of the security efforts documented here are rigorously applied to bridge security; including risk management, secure software development practices, auditing, vulnerability management, CI/CI and bug bounties. We use dedicated on-chain bridge monitoring.
44

55
## Bridge monitoring
66

0 commit comments

Comments
 (0)