Aggiunge la policy di responsible disclosure come allegato operativo.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@ -37,7 +37,7 @@ const allegatiByLocale: Record<SupportedLocale, AllegatiLocale> = {
|
||||
it: {
|
||||
page: {
|
||||
title: 'Allegati al Codice Etico — NexStudio',
|
||||
description: 'Template operativi allegati al Codice Etico NexStudio: adesione, NDA, checklist, DPIA, privacy, SBOM, retention, AI impact, piano formazione.',
|
||||
description: 'Template operativi allegati al Codice Etico NexStudio: adesione, NDA, checklist, DPIA, privacy, SBOM, retention, AI impact, piano formazione, responsible disclosure.',
|
||||
heading: 'Allegati e moduli operativi',
|
||||
lead: 'Documenti complementari al Codice Etico. Ciascun allegato è un template da personalizzare e adottare secondo le esigenze operative.',
|
||||
backLabel: '← Torna al Codice Etico',
|
||||
@ -583,12 +583,119 @@ const allegatiByLocale: Record<SupportedLocale, AllegatiLocale> = {
|
||||
],
|
||||
footer: 'Approvazione piano: HR _______ · CISO _______ · DPO _______ · Data _______',
|
||||
},
|
||||
{
|
||||
id: 'security-disclosure',
|
||||
heading: 'Policy di responsible disclosure e segnalazione vulnerabilità',
|
||||
description: 'Come segnalare vulnerabilità di sicurezza a NexStudio: canale, tempi di risposta, ambito e regole di buon senso (bug bounty soft).',
|
||||
intro:
|
||||
'Documento operativo collegato alla sezione 11 del Codice Etico (gestione vulnerabilità). Canale ufficiale: security@nexstudio.com. Un programma di bug bounty a premi monetari potrà essere aggiunto in seguito senza cambiare questo canale.',
|
||||
sections: [
|
||||
{
|
||||
title: '1. Scopo',
|
||||
content: [
|
||||
'Consentire a ricercatori e utenti di segnalare vulnerabilità in buona fede, con tempi di risposta definiti e senza rischio di azioni legali se rispettano questa policy.',
|
||||
'Proteggere i dati di clienti, pazienti e studi (LexAura / MediAura) e la disponibilità dei servizi SaaS.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '2. Ambito (in scope)',
|
||||
content: [
|
||||
'Siti e app web pubblici NexStudio (dominio principale e sottopagine IT/EN/TH).',
|
||||
'API e endpoint autenticati dei prodotti LexAura e MediAura esposti in produzione o staging pubblico.',
|
||||
'Infrastruttura cloud direttamente attribuibile a NexStudio e raggiungibile da Internet.',
|
||||
'Errori di configurazione che espongono dati personali, segreti, backup o pannelli di amministrazione.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '3. Fuori ambito (out of scope)',
|
||||
content: [
|
||||
'Attacchi DoS/DDoS, flood, stress test non concordati.',
|
||||
'Social engineering verso dipendenti, clienti o fornitori (phishing, pretexting).',
|
||||
'Spam, malware delivery, physical security.',
|
||||
'Vulnerabilità su prodotti di terze parti non gestiti da NexStudio, salvo misconfigurazione nostra.',
|
||||
'Report generati solo da scanner automatici senza PoC riproducibile.',
|
||||
'Finding già noti e in remediation (verificare risposta automatica o stato pubblico se disponibile).',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '4. Regole di test in buona fede',
|
||||
content: [
|
||||
'Non accedere, modificare o cancellare dati di terzi oltre lo stretto necessario per dimostrare il problema.',
|
||||
'Fermarsi immediatamente se si incontrano dati personali o sanitari reali; segnalare senza exfiltrare.',
|
||||
'Non eseguire exploit che degradino il servizio o compromettano altri utenti.',
|
||||
'Non richiedere riscatto o divulgare pubblicamente prima della coordinazione (embargo ragionevole).',
|
||||
'Usare account di test propri o ambienti staging quando disponibili.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '5. Come segnalare',
|
||||
content: [
|
||||
{ label: 'Canale', fields: ['Email: security@nexstudio.com (PGP opzionale, se pubblicato in seguito).'] },
|
||||
{
|
||||
label: 'Contenuto minimo della segnalazione',
|
||||
fields: [
|
||||
'Titolo sintetico',
|
||||
'URL / endpoint / componente',
|
||||
'Descrizione e impatto',
|
||||
'Passi per riprodurre (PoC)',
|
||||
'Severità stimata (Low/Medium/High/Critical)',
|
||||
'Contatto per follow-up',
|
||||
'Se i dati sono stati visti: categorie e volume (senza allegare i dati stessi)',
|
||||
],
|
||||
},
|
||||
],
|
||||
note: 'Oggetto consigliato: [SECURITY] breve titolo. Non allegare dump di dati reali.',
|
||||
},
|
||||
{
|
||||
title: '6. SLA di risposta e remediation',
|
||||
content: [
|
||||
{ label: 'Ack (ricezione)', fields: ['Entro 72 ore lavorative dalla segnalazione valida.'] },
|
||||
{ label: 'Triage iniziale', fields: ['Entro 5 giorni lavorativi: conferma in/out of scope e severità preliminare.'] },
|
||||
{
|
||||
label: 'Target di fix (indicativi)',
|
||||
fields: [
|
||||
'Critical: contenimento immediato; fix o mitigazione entro 7 giorni',
|
||||
'High: 14 giorni',
|
||||
'Medium: 30 giorni',
|
||||
'Low: 90 giorni o prossimo ciclo di release',
|
||||
],
|
||||
},
|
||||
{ label: 'Comunicazione', fields: ['Aggiornamenti al reporter fino a chiusura; eventuale advisory pubblico dopo fix, con credito se richiesto.'] },
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '7. Safe harbor',
|
||||
content: [
|
||||
'NexStudio non avvierà azioni legali contro chi segnala in buona fede rispettando questa policy e le leggi applicabili.',
|
||||
'La safe harbor non copre attività fuori ambito, furto di dati, estorsione o danni intenzionali.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '8. Riconoscimenti e bug bounty',
|
||||
content: [
|
||||
'Fase attuale (soft bounty): ringraziamento scritto e, se il reporter acconsente, menzione in hall of fame / advisory.',
|
||||
'Premi monetari o swag: non garantiti; potranno essere introdotti con griglia pubblica senza cambiare il canale security@.',
|
||||
'Duplicati e out-of-scope: ack cortese senza reward.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '9. Owner interni',
|
||||
content: [
|
||||
{ label: 'CISO / Security', fields: ['Triage, remediation, comunicazione al reporter.'] },
|
||||
{ label: 'DPO', fields: ['Coinvolto se la vulnerabilità implica dati personali o breach.'] },
|
||||
{ label: 'Legal', fields: ['Valutazione safe harbor e disclosure pubblica.'] },
|
||||
{ label: 'CTO', fields: ['Priorità tecnica e risorse di fix.'] },
|
||||
],
|
||||
},
|
||||
],
|
||||
footer: 'Approvazione policy: CISO _______ · CTO _______ · Legal _______ · Data _______',
|
||||
},
|
||||
],
|
||||
},
|
||||
en: {
|
||||
page: {
|
||||
title: 'Code of Ethics Annexes — NexStudio',
|
||||
description: 'Operational templates annexed to the NexStudio Code of Ethics: adhesion, NDA, checklist, DPIA, privacy, SBOM, retention, AI impact, training plan.',
|
||||
description: 'Operational templates annexed to the NexStudio Code of Ethics: adhesion, NDA, checklist, DPIA, privacy, SBOM, retention, AI impact, training plan, responsible disclosure.',
|
||||
heading: 'Annexes and operational forms',
|
||||
lead: 'Complementary documents to the Code of Ethics. Each annex is a template to be customized and adopted according to operational needs.',
|
||||
backLabel: '← Back to Code of Ethics',
|
||||
@ -1134,12 +1241,119 @@ const allegatiByLocale: Record<SupportedLocale, AllegatiLocale> = {
|
||||
],
|
||||
footer: 'Plan approval: HR _______ · CISO _______ · DPO _______ · Date _______',
|
||||
},
|
||||
{
|
||||
id: 'security-disclosure',
|
||||
heading: 'Responsible disclosure and vulnerability reporting policy',
|
||||
description: 'How to report security vulnerabilities to NexStudio: channel, response times, scope and good-faith rules (soft bug bounty).',
|
||||
intro:
|
||||
'Operational document linked to section 11 of the Code of Ethics (vulnerability management). Official channel: security@nexstudio.com. A paid bug bounty program may be added later without changing this channel.',
|
||||
sections: [
|
||||
{
|
||||
title: '1. Purpose',
|
||||
content: [
|
||||
'Allow researchers and users to report vulnerabilities in good faith, with defined response times and without legal risk if they follow this policy.',
|
||||
'Protect customer, patient and firm data (LexAura / MediAura) and SaaS availability.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '2. Scope (in scope)',
|
||||
content: [
|
||||
'Public NexStudio websites and web apps (main domain and IT/EN/TH subpages).',
|
||||
'Authenticated APIs and endpoints of LexAura and MediAura exposed in production or public staging.',
|
||||
'Cloud infrastructure directly attributable to NexStudio and reachable from the Internet.',
|
||||
'Misconfigurations exposing personal data, secrets, backups or admin panels.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '3. Out of scope',
|
||||
content: [
|
||||
'DoS/DDoS, flooding, uncoordinated stress tests.',
|
||||
'Social engineering of employees, customers or vendors (phishing, pretexting).',
|
||||
'Spam, malware delivery, physical security.',
|
||||
'Vulnerabilities in third-party products not operated by NexStudio, unless caused by our misconfiguration.',
|
||||
'Scanner-only reports without a reproducible PoC.',
|
||||
'Findings already known and in remediation.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '4. Good-faith testing rules',
|
||||
content: [
|
||||
'Do not access, modify or delete third-party data beyond what is strictly needed to demonstrate the issue.',
|
||||
'Stop immediately if real personal or health data is encountered; report without exfiltrating.',
|
||||
'Do not run exploits that degrade service or compromise other users.',
|
||||
'Do not demand ransom or disclose publicly before coordination (reasonable embargo).',
|
||||
'Use your own test accounts or staging environments when available.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '5. How to report',
|
||||
content: [
|
||||
{ label: 'Channel', fields: ['Email: security@nexstudio.com (optional PGP later, if published).'] },
|
||||
{
|
||||
label: 'Minimum report contents',
|
||||
fields: [
|
||||
'Short title',
|
||||
'URL / endpoint / component',
|
||||
'Description and impact',
|
||||
'Reproduction steps (PoC)',
|
||||
'Estimated severity (Low/Medium/High/Critical)',
|
||||
'Follow-up contact',
|
||||
'If data was seen: categories and volume (do not attach the data itself)',
|
||||
],
|
||||
},
|
||||
],
|
||||
note: 'Suggested subject: [SECURITY] short title. Do not attach dumps of real data.',
|
||||
},
|
||||
{
|
||||
title: '6. Response and remediation SLAs',
|
||||
content: [
|
||||
{ label: 'Ack (receipt)', fields: ['Within 72 business hours of a valid report.'] },
|
||||
{ label: 'Initial triage', fields: ['Within 5 business days: in/out of scope and preliminary severity.'] },
|
||||
{
|
||||
label: 'Indicative fix targets',
|
||||
fields: [
|
||||
'Critical: immediate containment; fix or mitigation within 7 days',
|
||||
'High: 14 days',
|
||||
'Medium: 30 days',
|
||||
'Low: 90 days or next release cycle',
|
||||
],
|
||||
},
|
||||
{ label: 'Communication', fields: ['Updates to the reporter until closure; optional public advisory after fix, with credit if requested.'] },
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '7. Safe harbor',
|
||||
content: [
|
||||
'NexStudio will not pursue legal action against good-faith reporters who follow this policy and applicable law.',
|
||||
'Safe harbor does not cover out-of-scope activity, data theft, extortion or intentional harm.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '8. Recognition and bug bounty',
|
||||
content: [
|
||||
'Current phase (soft bounty): written thanks and, if the reporter agrees, mention in a hall of fame / advisory.',
|
||||
'Cash or swag rewards: not guaranteed; may be introduced later with a public grid without changing the security@ channel.',
|
||||
'Duplicates and out-of-scope: polite ack without reward.',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '9. Internal owners',
|
||||
content: [
|
||||
{ label: 'CISO / Security', fields: ['Triage, remediation, reporter communication.'] },
|
||||
{ label: 'DPO', fields: ['Involved if the issue implies personal data or a breach.'] },
|
||||
{ label: 'Legal', fields: ['Safe harbor assessment and public disclosure.'] },
|
||||
{ label: 'CTO', fields: ['Technical priority and fix resources.'] },
|
||||
],
|
||||
},
|
||||
],
|
||||
footer: 'Policy approval: CISO _______ · CTO _______ · Legal _______ · Date _______',
|
||||
},
|
||||
],
|
||||
},
|
||||
th: {
|
||||
page: {
|
||||
title: 'ภาคผนวกประมวลจริยธรรม — NexStudio',
|
||||
description: 'เทมเพลตปฏิบัติการแนบท้ายประมวลจริยธรรม NexStudio: การยอมรับ, NDA, เช็กลิสต์, DPIA, ความเป็นส่วนตัว, SBOM, การเก็บรักษา, AI impact, แผนการฝึกอบรม',
|
||||
description: 'เทมเพลตปฏิบัติการแนบท้ายประมวลจริยธรรม NexStudio: การยอมรับ, NDA, เช็กลิสต์, DPIA, ความเป็นส่วนตัว, SBOM, การเก็บรักษา, AI impact, แผนการฝึกอบรม, responsible disclosure',
|
||||
heading: 'ภาคผนวกและแบบฟอร์มปฏิบัติการ',
|
||||
lead: 'เอกสารเสริมประมวลจริยธรรม แต่ละภาคผนวกเป็นเทมเพลตที่ต้องปรับแต่งและนำไปใช้ตามความต้องการเชิงปฏิบัติการ',
|
||||
backLabel: '← กลับไปประมวลจริยธรรม',
|
||||
@ -1683,6 +1897,113 @@ const allegatiByLocale: Record<SupportedLocale, AllegatiLocale> = {
|
||||
],
|
||||
footer: 'การอนุมัติแผน: HR _______ · CISO _______ · DPO _______ · วันที่ _______',
|
||||
},
|
||||
{
|
||||
id: 'security-disclosure',
|
||||
heading: 'นโยบาย responsible disclosure และการรายงานช่องโหว่',
|
||||
description: 'วิธีรายงานช่องโหว่ความปลอดภัยถึง NexStudio: ช่องทาง เวลาตอบสนอง ขอบเขต และกฎสุจริต (soft bug bounty)',
|
||||
intro:
|
||||
'เอกสารปฏิบัติการเชื่อมกับหมวด 11 ของประมวลจริยธรรม (การจัดการช่องโหว่) ช่องทางอย่างเป็นทางการ: security@nexstudio.com โปรแกรม bug bounty ที่มีรางวัลเงินอาจเพิ่มภายหลังโดยไม่เปลี่ยนช่องทางนี้',
|
||||
sections: [
|
||||
{
|
||||
title: '1. วัตถุประสงค์',
|
||||
content: [
|
||||
'ให้ผู้วิจัยและผู้ใช้รายงานช่องโหว่โดยสุจริต พร้อมเวลาตอบสนองที่กำหนด และไม่เสี่ยงต่อการดำเนินคดีหากปฏิบัติตามนโยบายนี้',
|
||||
'ปกป้องข้อมูลลูกค้า ผู้ป่วย และสำนักงาน (LexAura / MediAura) และความพร้อมใช้ของบริการ SaaS',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '2. ขอบเขต (in scope)',
|
||||
content: [
|
||||
'เว็บไซต์และเว็บแอปสาธารณะของ NexStudio (โดเมนหลักและหน้า IT/EN/TH)',
|
||||
'API และ endpoint ที่ต้องยืนยันตัวตนของ LexAura และ MediAura ใน production หรือ staging สาธารณะ',
|
||||
'โครงสร้างคลาวด์ที่เป็นของ NexStudio โดยตรงและเข้าถึงได้จากอินเทอร์เน็ต',
|
||||
'การตั้งค่าผิดพลาดที่เปิดเผยข้อมูลส่วนบุคคล ความลับ สำรอง หรือแผงผู้ดูแล',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '3. นอกขอบเขต (out of scope)',
|
||||
content: [
|
||||
'DoS/DDoS การ flood การทดสอบความเครียดโดยไม่ประสาน',
|
||||
'Social engineering ต่อพนักงาน ลูกค้า หรือผู้ให้บริการ (phishing pretexting)',
|
||||
'สแปม การส่งมัลแวร์ ความปลอดภัยทางกายภาพ',
|
||||
'ช่องโหว่ของผลิตภัณฑ์บุคคลที่สามที่ NexStudio ไม่ได้ดำเนินการ เว้นแต่เกิดจากการตั้งค่าผิดของเรา',
|
||||
'รายงานจากสแกนเนอร์อย่างเดียวโดยไม่มี PoC ที่ทำซ้ำได้',
|
||||
'ประเด็นที่ทราบแล้วและอยู่ระหว่าง remediation',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '4. กฎการทดสอบโดยสุจริต',
|
||||
content: [
|
||||
'อย่าเข้าถึง แก้ไข หรือลบข้อมูลของบุคคลที่สามเกินกว่าที่จำเป็นเพื่อพิสูจน์ปัญหา',
|
||||
'หยุดทันทีหากพบข้อมูลส่วนบุคคลหรือสุขภาพจริง; รายงานโดยไม่นำข้อมูลออก',
|
||||
'อย่ารัน exploit ที่ทำให้บริการแย่ลงหรือกระทบผู้ใช้อื่น',
|
||||
'อย่าเรียกค่าไถ่หรือเปิดเผยสาธารณะก่อนประสาน (embargo ที่สมเหตุสมผล)',
|
||||
'ใช้บัญชีทดสอบของตนเองหรือ staging เมื่อมี',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '5. วิธีรายงาน',
|
||||
content: [
|
||||
{ label: 'ช่องทาง', fields: ['อีเมล: security@nexstudio.com (PGP เป็นทางเลือกในภายหลังหากเผยแพร่)'] },
|
||||
{
|
||||
label: 'เนื้อหาขั้นต่ำของรายงาน',
|
||||
fields: [
|
||||
'ชื่อเรื่องสั้น',
|
||||
'URL / endpoint / ส่วนประกอบ',
|
||||
'คำอธิบายและผลกระทบ',
|
||||
'ขั้นตอนทำซ้ำ (PoC)',
|
||||
'ความรุนแรงโดยประมาณ (Low/Medium/High/Critical)',
|
||||
'ช่องทางติดต่อติดตาม',
|
||||
'หากเห็นข้อมูล: หมวดหมู่และปริมาณ (อย่าแนบข้อมูลจริง)',
|
||||
],
|
||||
},
|
||||
],
|
||||
note: 'หัวข้อแนะนำ: [SECURITY] ชื่อสั้น อย่าแนบ dump ของข้อมูลจริง',
|
||||
},
|
||||
{
|
||||
title: '6. SLA การตอบสนองและการแก้ไข',
|
||||
content: [
|
||||
{ label: 'Ack (รับเรื่อง)', fields: ['ภายใน 72 ชั่วโมงทำการนับจากรายงานที่ถูกต้อง'] },
|
||||
{ label: 'Triage เบื้องต้น', fields: ['ภายใน 5 วันทำการ: ยืนยัน in/out of scope และความรุนแรงเบื้องต้น'] },
|
||||
{
|
||||
label: 'เป้าหมายการแก้ไข (โดยประมาณ)',
|
||||
fields: [
|
||||
'Critical: กักกันทันที; แก้หรือบรรเทาภายใน 7 วัน',
|
||||
'High: 14 วัน',
|
||||
'Medium: 30 วัน',
|
||||
'Low: 90 วัน หรือรอบปล่อยถัดไป',
|
||||
],
|
||||
},
|
||||
{ label: 'การสื่อสาร', fields: ['อัปเดตผู้รายงานจนปิดเรื่อง; advisory สาธารณะหลังแก้ หากขอเครดิต'] },
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '7. Safe harbor',
|
||||
content: [
|
||||
'NexStudio จะไม่ดำเนินคดีกับผู้ที่รายงานโดยสุจริตและปฏิบัติตามนโยบายนี้กับกฎหมายที่ใช้บังคับ',
|
||||
'Safe harbor ไม่ครอบคลุมกิจกรรมนอกขอบเขต การขโมยข้อมูล การขู่กรรโชก หรือความเสียหายโดยเจตนา',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '8. การยอมรับและ bug bounty',
|
||||
content: [
|
||||
'ระยะปัจจุบัน (soft bounty): คำขอบคุณเป็นลายลักษณ์อักษร และหากผู้รายงานยินยอม ระบุชื่อใน hall of fame / advisory',
|
||||
'รางวัลเงินหรือของที่ระลึก: ไม่รับประกัน; อาจมีภายหลังพร้อมตารางสาธารณะโดยไม่เปลี่ยนช่องทาง security@',
|
||||
'รายการซ้ำและนอกขอบเขต: ack สุภาพโดยไม่มีรางวัล',
|
||||
],
|
||||
},
|
||||
{
|
||||
title: '9. ผู้รับผิดชอบภายใน',
|
||||
content: [
|
||||
{ label: 'CISO / Security', fields: ['Triage การแก้ไข การสื่อสารกับผู้รายงาน'] },
|
||||
{ label: 'DPO', fields: ['เกี่ยวข้องหากช่องโหว่เกี่ยวกับข้อมูลส่วนบุคคลหรือ breach'] },
|
||||
{ label: 'Legal', fields: ['ประเมิน safe harbor และการเปิดเผยสาธารณะ'] },
|
||||
{ label: 'CTO', fields: ['ลำดับความสำคัญทางเทคนิคและทรัพยากรแก้ไข'] },
|
||||
],
|
||||
},
|
||||
],
|
||||
footer: 'การอนุมัตินโยบาย: CISO _______ · CTO _______ · Legal _______ · วันที่ _______',
|
||||
},
|
||||
],
|
||||
},
|
||||
};
|
||||
|
||||
@ -147,7 +147,11 @@ type CodiceEticoLocale = {
|
||||
};
|
||||
ai: { title: string; items: readonly (string | LabeledItem)[] };
|
||||
conflitti: { title: string; items: readonly string[] };
|
||||
lineeOperative: { title: string; items: readonly LabeledItem[] };
|
||||
lineeOperative: {
|
||||
title: string;
|
||||
items: readonly LabeledItem[];
|
||||
disclosureLinkLabel: string;
|
||||
};
|
||||
governance: { title: string; items: readonly LabeledItem[] };
|
||||
onboarding: {
|
||||
title: string;
|
||||
@ -506,7 +510,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
},
|
||||
{
|
||||
label: 'Gestione vulnerabilità',
|
||||
text: 'canale pubblico o privato per segnalazioni (bug bounty o indirizzo dedicato security@), conferma di ricezione entro 72 ore, piano di remediation con tempi stimati.',
|
||||
text: 'canale ufficiale security@nexstudio.com secondo la policy di responsible disclosure (allegato); ack entro 72 ore, remediation per severità.',
|
||||
},
|
||||
{
|
||||
label: 'Patch management',
|
||||
@ -517,6 +521,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
text: 'changelog, impatti noti e raccomandazioni operative.',
|
||||
},
|
||||
],
|
||||
disclosureLinkLabel: 'Apri la policy di responsible disclosure →',
|
||||
},
|
||||
governance: {
|
||||
title: '12. Governance, ruoli e responsabilità',
|
||||
@ -618,6 +623,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
'Policy di retention dei dati (tempi e giustificazioni).',
|
||||
'Template per valutazione d’impatto AI/ML.',
|
||||
'Piano di formazione — onboarding 90 giorni e formazione annuale.',
|
||||
'Policy di responsible disclosure e segnalazione vulnerabilità.',
|
||||
],
|
||||
},
|
||||
approvazione: {
|
||||
@ -658,7 +664,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
title: 'Note pratiche e prossimi passi consigliati',
|
||||
items: [
|
||||
'Personalizzare il documento con il nome ufficiale della società (se diverso dal marchio operativo), firme e riferimenti legali locali a Bangkok.',
|
||||
'Allegare i template elencati come documenti separati e implementare i canali tecnici per segnalazioni e bug bounty.',
|
||||
'Implementare i canali tecnici per segnalazioni etiche (piattaforma anonima); la policy di responsible disclosure (security@) è già in allegato.',
|
||||
'Applicare il Piano di formazione (allegato operativo): onboarding 90 giorni e refresh annuale; HR tiene il registro di completamento.',
|
||||
],
|
||||
},
|
||||
@ -999,7 +1005,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
},
|
||||
{
|
||||
label: 'Vulnerability management',
|
||||
text: 'public or private reporting channel (bug bounty or dedicated security@ address), acknowledgement within 72 hours, remediation plan with estimated timelines.',
|
||||
text: 'official channel security@nexstudio.com per the responsible disclosure policy (annex); ack within 72 hours, remediation by severity.',
|
||||
},
|
||||
{
|
||||
label: 'Patch management',
|
||||
@ -1010,6 +1016,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
text: 'changelog, known impacts and operational recommendations.',
|
||||
},
|
||||
],
|
||||
disclosureLinkLabel: 'Open the responsible disclosure policy →',
|
||||
},
|
||||
governance: {
|
||||
title: '12. Governance, roles and responsibilities',
|
||||
@ -1111,6 +1118,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
'Data retention policy (timelines and justifications).',
|
||||
'AI/ML impact assessment template.',
|
||||
'Training plan — 90-day onboarding and annual refresh.',
|
||||
'Responsible disclosure and vulnerability reporting policy.',
|
||||
],
|
||||
},
|
||||
approvazione: {
|
||||
@ -1151,7 +1159,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
title: 'Practical notes and recommended next steps',
|
||||
items: [
|
||||
'Customize the document with the official company name (if different from the operating brand), signatures and local legal references in Bangkok.',
|
||||
'Attach the listed templates as separate documents and implement technical channels for reporting and bug bounty.',
|
||||
'Implement technical channels for ethics reporting (anonymous platform); the responsible disclosure policy (security@) is already in the annexes.',
|
||||
'Apply the Training plan (operational annex): 90-day onboarding and annual refresh; HR keeps the completion register.',
|
||||
],
|
||||
},
|
||||
@ -1492,7 +1500,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
},
|
||||
{
|
||||
label: 'การจัดการช่องโหว่',
|
||||
text: 'ช่องทางสาธารณะหรือส่วนตัวสำหรับการรายงาน (bug bounty หรือที่อยู่ security@ เฉพาะ) ยืนยันการรับภายใน 72 ชั่วโมง แผน remediation พร้อมระยะเวลาโดยประมาณ',
|
||||
text: 'ช่องทางอย่างเป็นทางการ security@nexstudio.com ตามนโยบาย responsible disclosure (ภาคผนวก); ack ภายใน 72 ชั่วโมง remediation ตามความรุนแรง',
|
||||
},
|
||||
{
|
||||
label: 'Patch management',
|
||||
@ -1503,6 +1511,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
text: 'changelog ผลกระทบที่ทราบ และข้อแนะนำเชิงปฏิบัติการ',
|
||||
},
|
||||
],
|
||||
disclosureLinkLabel: 'เปิดนโยบาย responsible disclosure →',
|
||||
},
|
||||
governance: {
|
||||
title: '12. การกำกับดูแล บทบาท และความรับผิดชอบ',
|
||||
@ -1604,6 +1613,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
'นโยบายการเก็บรักษาข้อมูล (ระยะเวลาและเหตุผล)',
|
||||
'เทมเพลตการประเมินผลกระทบ AI/ML',
|
||||
'แผนการฝึกอบรม — ปฐมนิเทศ 90 วัน และการทบทวนประจำปี',
|
||||
'นโยบาย responsible disclosure และการรายงานช่องโหว่',
|
||||
],
|
||||
},
|
||||
approvazione: {
|
||||
@ -1644,7 +1654,7 @@ const codiceEticoByLocale: Record<SupportedLocale, CodiceEticoLocale> = {
|
||||
title: 'บันทึกเชิงปฏิบัติและขั้นตอนถัดไปที่แนะนำ',
|
||||
items: [
|
||||
'ปรับแต่งเอกสารด้วยชื่อบริษัทอย่างเป็นทางการ (หากต่างจากแบรนด์ปฏิบัติการ) ลายเซ็น และการอ้างอิงทางกฎหมายท้องถิ่นในกรุงเทพฯ',
|
||||
'แนบเทมเพลตที่ระบุเป็นเอกสารแยก และจัดทำช่องทางเทคนิคสำหรับการรายงานและ bug bounty',
|
||||
'จัดทำช่องทางเทคนิคสำหรับการรายงานจริยธรรม (แพลตฟอร์มนิรนาม); นโยบาย responsible disclosure (security@) อยู่ในภาคผนวกแล้ว',
|
||||
'ใช้แผนการฝึกอบรม (ภาคผนวกปฏิบัติการ): ปฐมนิเทศ 90 วัน และการทบทวนประจำปี; HR รักษาทะเบียนการสำเร็จ',
|
||||
],
|
||||
},
|
||||
|
||||
@ -203,6 +203,14 @@ const isLabeled = (item: string | { label: string; text: string }): item is { la
|
||||
))
|
||||
}
|
||||
</ul>
|
||||
<p class="mt-3 text-sm">
|
||||
<a
|
||||
class={link}
|
||||
href={`/${currentLocale === 'it' ? '' : currentLocale + '/'}allegati#security-disclosure`}
|
||||
>
|
||||
{c.lineeOperative.disclosureLinkLabel}
|
||||
</a>
|
||||
</p>
|
||||
|
||||
<h2 id="governance">{c.governance.title}</h2>
|
||||
<ul>
|
||||
|
||||
Reference in New Issue
Block a user