Skip to content

Conversation

@repo-mountie
Copy link

TL;DR 🏎️

Your repo is missing a compliance audit file so I've created this PR with a template that you can update with the correct PIA and STRA status (status options in the table below). If you'd like me to do this for you, skip to the commands section below.

Compliance

Projects in our organization (bcgov) need to complete a Privacy Impact Assessment (PIA) and Security Threat & Risk Assessment (STRA) before they go live in production. Since every ministry has their own way of doing both the STRA and PIA we don't enforce that projects do them, only that they report on the current status.

To help with reporting, I've added a compliance audit file as part of this pull request. Please checkout this branch and edit update status as needed. Here is a table of possible states:

StatusDescription
TBDIf you're surprised by this news, use this state. I'll let you talk to your MISO and check back later.
in-progressUse this state when your assessment(s) are underway.
completedUse this state when your assessment(s) are completed. 🙌 🎉
not-requiredYou have consulted with your MISO or Privacy Officer and they agree that no PIA or STRA is required.

Here is what a completed audit file might look like:

name: compliancedescription: | This document is used to track a projects PIA and STRA compliance.spec: - name: PIAstatus: in-progresslast-updated: '2019-11-22T00:03:52.138Z' - name: STRAstatus: completedlast-updated: '2019-11-22T00:03:52.138Z'

For more information check out the BC Policy Framework for GitHub.

Pro Tip 🤓

  • If you're not sure what to do add a comment below with the command @repo-mountie help in it; a real-live-person will reply back to help you out.
  • Leverage this PR to document the history of your PIA and STRA thus far by adding a comment or two.

Commands 🤖

I can update the status of the PIA and STRA for you; you'll just need to merge the PR when I'm done. You can find the available status values in the table above. Below are some commands I understand:

CommandDescription
@repo-mountie helpYou're freaking out and want to talk to a person.
@repo-mountie update-pia STATUSYou want me to update the PIA status.
@repo-mountie update-stra STATUSYou want me to update the STRA status.

Examples

@repo-mountie update-pia completed@repo-mountie update-stra in-progress

Signed-off-by: repo-mountie <[email protected]>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rshourou