2014 lines
164 KiB
TypeScript
2014 lines
164 KiB
TypeScript
/**
|
||
* Allegati al Codice Etico — 9 template operativi.
|
||
* Ogni allegato ha un ID, titolo, descrizione e sezioni di contenuto.
|
||
*/
|
||
import type { SupportedLocale } from './home/navigation';
|
||
|
||
export type AllegatoContent = string | string[] | { label: string; text: string }[] | { label: string; fields: string[] }[];
|
||
|
||
export type AllegatoSection = {
|
||
title?: string;
|
||
intro?: string;
|
||
content: AllegatoContent;
|
||
note?: string;
|
||
};
|
||
|
||
export type Allegato = {
|
||
id: string;
|
||
heading: string;
|
||
description: string;
|
||
intro?: string;
|
||
sections: AllegatoSection[];
|
||
footer?: string;
|
||
};
|
||
|
||
type AllegatiLocale = {
|
||
page: {
|
||
title: string;
|
||
description: string;
|
||
heading: string;
|
||
lead: string;
|
||
backLabel: string;
|
||
};
|
||
allegati: Allegato[];
|
||
};
|
||
|
||
const allegatiByLocale: Record<SupportedLocale, AllegatiLocale> = {
|
||
it: {
|
||
page: {
|
||
title: 'Allegati al Codice Etico — NexStudio',
|
||
description: 'Template operativi allegati al Codice Etico NexStudio: adesione, NDA, checklist, DPIA, privacy, SBOM, retention, AI impact, piano formazione, responsible disclosure.',
|
||
heading: 'Allegati e moduli operativi',
|
||
lead: 'Documenti complementari al Codice Etico. Ciascun allegato è un template da personalizzare e adottare secondo le esigenze operative.',
|
||
backLabel: '← Torna al Codice Etico',
|
||
},
|
||
allegati: [
|
||
{
|
||
id: 'adesione',
|
||
heading: 'Dichiarazione personale di adesione al Codice Etico',
|
||
description: 'Modulo da far firmare a ogni collaboratore in fase di onboarding.',
|
||
intro: 'Da compilare, firmare e conservare nel fascicolo personale.',
|
||
sections: [
|
||
{
|
||
content: [
|
||
{ label: 'Nome e cognome', fields: ['_____________________________'] },
|
||
{ label: 'Ruolo / qualifica', fields: ['_____________________________'] },
|
||
{ label: 'Data di onboarding', fields: ['_____________________________'] },
|
||
{ label: 'Firma', fields: ['_____________________________'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Dichiarazione',
|
||
intro: 'Il/La sottoscritto/a dichiara:',
|
||
content: [
|
||
'Di aver ricevuto, letto e compreso il Codice Etico di NexStudio nella sua versione vigente.',
|
||
'Di impegnarsi a rispettarne i principi, le regole di comportamento e le procedure in esso contenute.',
|
||
'Di aver ricevuto o di ricevere secondo il piano formativo la formazione obbligatoria su sicurezza informatica, privacy (PDPA e GDPR), gestione dati sensibili, uso responsabile dell’AI e pratiche di coding sicuro.',
|
||
'Di impegnarsi a segnalare, in buona fede e attraverso i canali previsti, eventuali violazioni del Codice di cui dovesse venire a conoscenza.',
|
||
'Di essere consapevole che la violazione del Codice può comportare provvedimenti disciplinari proporzionati, fino alla risoluzione del rapporto contrattuale.',
|
||
'Di accettare che la presente dichiarazione venga conservata nel proprio fascicolo personale e utilizzata ai fini della governance aziendale.',
|
||
],
|
||
},
|
||
],
|
||
footer: 'Luogo e data: _____________________ · Firma: _____________________',
|
||
},
|
||
{
|
||
id: 'nda',
|
||
heading: 'Template NDA e clausole minime per fornitori e sub-processori',
|
||
description: 'Accordo di riservatezza standard per collaboratori esterni, consulenti, fornitori e sub-processori.',
|
||
intro: 'Il presente template definisce le clausole minime di riservatezza. Adattare la parte introduttiva (parti, oggetto, durata) al rapporto specifico.',
|
||
sections: [
|
||
{
|
||
title: '1. Definizione di Informazioni Confidenziali',
|
||
content: [
|
||
'Per "Informazioni Confidenziali" si intende ogni dato, informazione, documento, know-how, codice sorgente, specifica tecnica, strategia commerciale, dato personale o sensibile, comunicazione o materiale — in qualsiasi forma (scritta, orale, elettronica, visiva) — che una parte (il "Divulgante") comunica all’altra (il "Ricevente") in relazione all’oggetto del rapporto, indipendentemente dal fatto che sia espressamente contrassegnato come confidenziale.',
|
||
'Rientrano nelle Informazioni Confidenziali anche i dati personali trattati per conto del Titolare, i dati relativi a pazienti, clienti e assistiti (per i perimetri Legal Tech e Health Tech), i log di sistema, le credenziali e i risultati di test e audit.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Obblighi del Ricevente',
|
||
content: [
|
||
'Utilizzare le Informazioni Confidenziali esclusivamente per le finalità concordate e per l’esecuzione del rapporto contrattuale.',
|
||
'Non divulgare, copiare, riprodurre o distribuire le Informazioni Confidenziali a terzi senza preventiva autorizzazione scritta del Divulgante.',
|
||
'Limitare l’accesso alle Informazioni Confidenziali ai soli soggetti autorizzati che abbiano necessità di conoscerle e che siano vincolati da obblighi di riservatezza almeno equivalenti.',
|
||
'Adottare misure di sicurezza tecniche e organizzative adeguate per proteggere le Informazioni Confidenziali da accessi non autorizzati, perdita, furto o divulgazione.',
|
||
'In caso di sub-affidamento (sub-processing), richiedere la preventiva autorizzazione scritta e imporre al sub-processore obblighi contrattuali equivalenti.',
|
||
],
|
||
},
|
||
{
|
||
title: '3. Esclusioni',
|
||
content: [
|
||
'Informazioni già di pubblico dominio senza violazione del presente accordo.',
|
||
'Informazioni già in possesso del Ricevente prima della divulgazione, come documentato.',
|
||
'Informazioni ricevute legittimamente da terzi senza obblighi di riservatezza.',
|
||
'Informazioni che il Ricevente è tenuto a divulgare per obbligo di legge o ordine dell’autorità (previa notifica al Divulgante, ove consentito).',
|
||
],
|
||
},
|
||
{
|
||
title: '4. Notifica in caso di violazione (Breach Notification)',
|
||
content: [
|
||
'Il Ricevente deve notificare al Divulgante qualsiasi accesso non autorizzato, perdita o divulgazione di Informazioni Confidenziali entro 24 ore dalla scoperta, fornendo: descrizione dell’evento, dati e categorie di dati coinvolti, misure adottate o proposte per mitigare gli effetti, punto di contatto per informazioni.',
|
||
],
|
||
},
|
||
{
|
||
title: '5. Durata e restituzione',
|
||
content: [
|
||
'L’obbligo di riservatezza permane per tutta la durata del rapporto e per i 5 anni successivi alla sua cessazione, salvo obblighi di legge più estesi.',
|
||
'Alla cessazione del rapporto, il Ricevente deve restituire o distruggere tutte le Informazioni Confidenziali, fornendo attestazione scritta.',
|
||
],
|
||
},
|
||
{
|
||
title: '6. Misure di sicurezza equivalenti',
|
||
content: [
|
||
'Crittografia a riposo e in transito con algoritmi aggiornati (minimo AES-256, TLS 1.3).',
|
||
'Controllo degli accessi con principio del privilegio minimo e MFA obbligatorio.',
|
||
'Logging immutabile per accessi a dati sensibili.',
|
||
'Procedure di gestione incidenti documentate.',
|
||
'Formazione del personale su sicurezza e privacy.',
|
||
],
|
||
},
|
||
{
|
||
title: '7. Legge applicabile e foro competente',
|
||
content: [
|
||
'Legge thailandese, con possibile rinvio a clausole GDPR/PDPA per i trattamenti di dati personali. Foro competente: Bangkok, Thailandia, salvo diverso accordo scritto.',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'checklist-prerelease',
|
||
heading: 'Checklist pre-release — Security & Privacy',
|
||
description: 'Lista di controllo obbligatoria prima di ogni rilascio in produzione.',
|
||
intro: 'Da compilare a cura del team di sviluppo e validare dal CISO/referente sicurezza. Ogni item deve ricevere check (✓), N/A (non applicabile) o ✗ con nota.',
|
||
sections: [
|
||
{
|
||
title: 'Sicurezza',
|
||
content: [
|
||
{ label: 'Code review completata e approvata', fields: ['[ ]'] },
|
||
{ label: 'Test automatici superati (CI verde)', fields: ['[ ]'] },
|
||
{ label: 'Analisi statica del codice (SAST) senza vulnerabilità critiche o high', fields: ['[ ]'] },
|
||
{ label: 'Analisi delle dipendenze (SCA) senza vulnerabilità note con CVSS ≥ 7', fields: ['[ ]'] },
|
||
{ label: 'Penetration test o scansione dinamica (DAST) eseguita su build pre-release', fields: ['[ ]'] },
|
||
{ label: 'Nessuna credenziale, token o segreto hardcodato nel codice', fields: ['[ ]'] },
|
||
{ label: 'Intestazioni di sicurezza HTTP configurate (HSTS, CSP, X-Frame-Options, ecc.)', fields: ['[ ]'] },
|
||
{ label: 'CORS configurato correttamente (nessun * su origini sensibili)', fields: ['[ ]'] },
|
||
{ label: 'Rate limiting attivo sugli endpoint pubblici', fields: ['[ ]'] },
|
||
{ label: 'Dipendenze aggiornate all’ultima versione stabile (o patch di sicurezza applicate)', fields: ['[ ]'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Privacy e dati',
|
||
content: [
|
||
{ label: 'Nessun dato personale reale negli ambienti di test (solo dati sintetici/anonimizzati)', fields: ['[ ]'] },
|
||
{ label: 'Crittografia a riposo abilitata per tutti i dati sensibili', fields: ['[ ]'] },
|
||
{ label: 'Crittografia in transito (TLS 1.3) attiva su tutti gli endpoint', fields: ['[ ]'] },
|
||
{ label: 'Logging privo di dati personali o sensibili in chiaro', fields: ['[ ]'] },
|
||
{ label: 'Meccanismi di consenso verificabili e registrati (se applicabile)', fields: ['[ ]'] },
|
||
{ label: 'Procedure di cancellazione/diritto all’oblio testate e funzionanti', fields: ['[ ]'] },
|
||
{ label: 'Politica di retention implementata e verificata', fields: ['[ ]'] },
|
||
{ label: 'DPIA aggiornata per i trattamenti coinvolti nel rilascio', fields: ['[ ]'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Operazioni',
|
||
content: [
|
||
{ label: 'Piano di rollback documentato e testato', fields: ['[ ]'] },
|
||
{ label: 'Changelog compilato con impatti noti', fields: ['[ ]'] },
|
||
{ label: 'Notifica agli stakeholder interni (supporto, security, DPO)', fields: ['[ ]'] },
|
||
{ label: 'Monitoraggio e alerting configurati per le nuove funzionalità', fields: ['[ ]'] },
|
||
],
|
||
note: 'Firme: Sviluppatore _______ Reviewer _______ CISO/DPO _______ Data _______',
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'incident-management',
|
||
heading: 'Gestione incidenti — Flowchart e template di notifica',
|
||
description: 'Procedura operativa e modello di comunicazione per la gestione degli incidenti di sicurezza e violazioni dei dati.',
|
||
sections: [
|
||
{
|
||
title: 'Flowchart: fasi della gestione incidenti',
|
||
content: [
|
||
'1. RILEVAZIONE — L’incidente viene rilevato da: sistema di monitoring automatico, segnalazione interna, bug bounty/reporter esterno, notifica di un fornitore o partner.',
|
||
'2. TRIAGE E CLASSIFICAZIONE (max 1 ora) — Il team di sicurezza valuta: tipo di incidente (violazione dati, accesso non autorizzato, malware, DDoS, ecc.), severità (bassa/media/alta/critica), perimetro coinvolto (piattaforma, Legal Tech, Health Tech), dati coinvolti (personali, sensibili, sanitari, legali).',
|
||
'3. CONTAINMENT (immediato) — Isolare i sistemi compromessi, revocare credenziali o token esposti, bloccare IP o account malevoli, attivare il team di risposta designato.',
|
||
'4. ERADICAZIONE — Rimuovere la causa root (patch, riconfigurazione, rimozione malware), verificare che non ci siano backdoor o persistenza, documentare le azioni intraprese.',
|
||
'5. RECOVERY — Ripristinare i sistemi da backup puliti, applicare patch e mitigazioni, validare il funzionamento in ambiente isolato prima del ritorno in produzione.',
|
||
'6. NOTIFICA — Entro 72 ore dalla scoperta: notificare il DPO e il Legal & Compliance; se violazione di dati personali, valutare obbligo di notifica all’autorità (PDPA/GDPR) e agli interessati. Usare il template di notifica (vedi sotto).',
|
||
'7. POST-MORTEM (entro 5 giorni lavorativi) — Analisi delle cause root, lezioni apprese, aggiornamento playbook e controlli di sicurezza, comunicazione interna (senza colpevolizzare).',
|
||
],
|
||
},
|
||
{
|
||
title: 'Template notifica incidente',
|
||
intro: 'Da inviare internamente e, se richiesto, esternamente.',
|
||
content: [
|
||
{ label: 'ID Incidente', fields: ['INC-YYYY-NNN'] },
|
||
{ label: 'Data e ora rilevazione', fields: ['_____________________'] },
|
||
{ label: 'Data e ora contenimento', fields: ['_____________________'] },
|
||
{ label: 'Severità', fields: ['[ ] Bassa [ ] Media [ ] Alta [ ] Critica'] },
|
||
{ label: 'Tipo', fields: ['[ ] Violazione dati [ ] Accesso non autorizzato [ ] Malware [ ] DDoS [ ] Altro: ___'] },
|
||
{ label: 'Perimetro', fields: ['[ ] Piattaforma [ ] Legal Tech / LexAura [ ] Health Tech / MediAura'] },
|
||
{ label: 'Sistemi coinvolti', fields: ['_____________________'] },
|
||
{ label: 'Dati coinvolti', fields: ['Categorie: ___ Numero interessati stimato: ___'] },
|
||
{ label: 'Descrizione', fields: ['_____________________'] },
|
||
{ label: 'Azioni intraprese', fields: ['_____________________'] },
|
||
{ label: 'Misure per gli interessati', fields: ['_____________________'] },
|
||
{ label: 'Punto di contatto', fields: ['Nome: ___ Email: ___ Telefono: ___'] },
|
||
{ label: 'Compilato da', fields: ['_____________________'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'dpia',
|
||
heading: 'Modello DPIA semplificato ed esempio compilato',
|
||
description: 'Data Protection Impact Assessment — modello base conforme a PDPA e GDPR.',
|
||
sections: [
|
||
{
|
||
title: 'Modello DPIA — Sezioni obbligatorie',
|
||
content: [
|
||
{ label: '1. Titolo del trattamento', fields: ['Descrizione sintetica del trattamento oggetto di valutazione.'] },
|
||
{ label: '2. Titolare e responsabili', fields: ['Titolare: ___ Responsabile/i: ___ Sub-responsabili: ___ DPO: ___'] },
|
||
{ label: '3. Finalità del trattamento', fields: ['Descrivere perché i dati vengono trattati, base giuridica e necessità.'] },
|
||
{ label: '4. Categorie di dati', fields: ['[ ] Personali comuni [ ] Particolari (salute, legali, biometrici) [ ] Giudiziari'] },
|
||
{ label: '5. Categorie di interessati', fields: ['[ ] Pazienti [ ] Clienti di studi [ ] Dipendenti [ ] Utenti piattaforma [ ] Altro: ___'] },
|
||
{ label: '6. Operazioni di trattamento', fields: ['Raccolta, registrazione, organizzazione, conservazione, consultazione, comunicazione, cancellazione, ecc.'] },
|
||
{ label: '7. Tecnologie utilizzate', fields: ['Database, cloud, API, AI/ML, etc.'] },
|
||
{ label: '8. Valutazione dei rischi', fields: ['Probabilità × Impatto per ciascun rischio identificato. Misure di mitigazione previste.'] },
|
||
{ label: '9. Misure di sicurezza', fields: ['Crittografia, controllo accessi, logging, backup, ecc.'] },
|
||
{ label: '10. Consultazione DPO', fields: ['Parere del DPO: ___ Data: ___'] },
|
||
{ label: '11. Decisione finale', fields: ['[ ] Rischio accettabile [ ] Rischio mitigato [ ] Necessaria consultazione autorità [ ] Trattamento da non avviare'] },
|
||
{ label: '12. Data e firme', fields: ['Compilatore: ___ DPO: ___ Titolare: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Esempio compilato — MediAura: gestione dati clinici in cloud',
|
||
content: [
|
||
{ label: '1. Titolo', fields: ['Gestione e archiviazione dati clinici dei pazienti su piattaforma MediAura (cloud, Bangkok).'] },
|
||
{ label: '2. Titolare e responsabili', fields: ['Titolare: studio medico/clinica sottoscrittrice. Responsabile: NexStudio. Sub-responsabili: cloud provider certificato ISO 27001.'] },
|
||
{ label: '3. Finalità', fields: ['Archiviazione e consultazione di dati clinici per supporto alla pratica medica. Base giuridica: esecuzione del contratto e consenso del paziente (informativa firmata).'] },
|
||
{ label: '4. Categorie dati', fields: ['Particolari: dati sanitari (diagnosi, prescrizioni, referti). Personali comuni: anagrafica, contatti.'] },
|
||
{ label: '5. Interessati', fields: ['Pazienti (adulti e minori tramite tutori).'] },
|
||
{ label: '6. Operazioni', fields: ['Raccolta, registrazione, organizzazione, conservazione, consultazione da personale autorizzato, cancellazione su richiesta.'] },
|
||
{ label: '7. Tecnologie', fields: ['Database cifrato (AES-256), API REST con TLS 1.3, AI per suggerimenti clinici (supervisione umana obbligatoria).'] },
|
||
{ label: '8. Rischi', fields: ['Accesso non autorizzato a dati sanitari (probabilità bassa, impatto alto → mitigato con MFA, cifratura e audit log). Perdita dati (probabilità bassa, impatto critico → mitigato con backup giornalieri, disaster recovery testato).'] },
|
||
{ label: '9. Misure sicurezza', fields: ['Crittografia a riposo AES-256 e in transito TLS 1.3. MFA obbligatorio. Log immutabili. Backup automatico giornaliero. Test di ripristino trimestrale.'] },
|
||
{ label: '10. DPO', fields: ['Parere favorevole con raccomandazione di audit annuale.'] },
|
||
{ label: '11. Decisione', fields: ['Rischio mitigato — trattamento approvato con revisione annuale.'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'privacy-notice',
|
||
heading: 'Modello informativa privacy e modulo consenso',
|
||
description: 'Template di informativa privacy conforme a PDPA e GDPR, con modulo consenso integrato.',
|
||
sections: [
|
||
{
|
||
title: 'Informativa sul trattamento dei dati personali',
|
||
intro: 'Ai sensi del PDPA (Thailandia) e, ove applicabile, del GDPR (UE).',
|
||
content: [
|
||
{ label: 'Titolare del trattamento', fields: ['[Nome studio / struttura], con sede in [indirizzo], email: [___], telefono: [___].'] },
|
||
{ label: 'Responsabile del trattamento (fornitore piattaforma)', fields: ['NexStudio, Bangkok, Thailandia, email: privacy@nexstudio.com.'] },
|
||
{ label: 'Finalità del trattamento', fields: ['Gestione dei servizi [legali/sanitari], archiviazione documentale, comunicazioni relative al servizio, adempimenti di legge.'] },
|
||
{ label: 'Base giuridica', fields: ['[Consenso dell’interessato / Esecuzione del contratto / Obbligo legale / Interesse legittimo].'] },
|
||
{ label: 'Categorie di dati trattati', fields: ['Dati anagrafici e di contatto. Dati relativi alla pratica [legale/sanitaria]. [Se sanitario: dati sulla salute ai sensi dell’art. 9 GDPR / PDPA].'] },
|
||
{ label: 'Periodo di conservazione', fields: ['[X anni] dalla conclusione del rapporto o come previsto dalla policy di retention.'] },
|
||
{ label: 'Destinatari dei dati', fields: ['Personale autorizzato del Titolare. NexStudio (responsabile del trattamento). Fornitori di servizi cloud (sub-responsabili con garanzie contrattuali). Autorità pubbliche, se richiesto per legge.'] },
|
||
{ label: 'Trasferimenti internazionali', fields: ['[Descrivere se i dati sono trasferiti fuori dalla Thailandia/UE e su quale base giuridica].'] },
|
||
{ label: 'Diritti dell’interessato', fields: ['Accesso, rettifica, cancellazione, limitazione, portabilità, opposizione, revoca del consenso. Per esercitare i diritti, contattare il Titolare all’indirizzo sopra indicato.'] },
|
||
{ label: 'Reclami', fields: ['L’interessato ha diritto di proporre reclamo all’autorità di controllo competente (PDPC in Thailandia / Garante Privacy nell’UE).'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Modulo di consenso',
|
||
intro: 'Da compilare e firmare dall’interessato.',
|
||
content: [
|
||
'Io sottoscritto/a _____________________, nato/a il ____________,',
|
||
'dichiaro di aver ricevuto e letto l’informativa sul trattamento dei dati personali.',
|
||
'',
|
||
'[ ] Acconsento al trattamento dei miei dati personali per le finalità indicate nell’informativa.',
|
||
'[ ] Acconsento al trattamento dei miei dati particolari (es. dati sanitari / dati legali) per le finalità indicate.',
|
||
'[ ] Acconsento alla comunicazione dei miei dati ai soggetti indicati nell’informativa.',
|
||
'',
|
||
'Data: ____________ Firma: _____________________',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'sbom',
|
||
heading: 'Template SBOM — Software Bill of Materials',
|
||
description: 'Inventario dei componenti software, licenze e vulnerabilità, in formato leggibile.',
|
||
sections: [
|
||
{
|
||
title: 'Istruzioni',
|
||
intro: 'Compilare per ogni componente open source o di terze parti utilizzato nel prodotto. Aggiornare a ogni release.',
|
||
content: [
|
||
'Generare automaticamente con strumenti come: CycloneDX, SPDX, Syft, Trivy, OWASP Dependency-Track.',
|
||
'Il formato raccomandato è CycloneDX JSON o SPDX tag-value.',
|
||
'Di seguito il template in formato tabellare per revisione manuale.',
|
||
],
|
||
},
|
||
{
|
||
title: 'Inventario componenti',
|
||
content: [
|
||
{ label: 'Nome componente', fields: ['Versione', 'Licenza', 'Tipo licenza (copyleft/permissiva)', 'Fornitore/URL', 'Utilizzo nel prodotto', 'Vulnerabilità note (CVE)', 'CVSS score', 'Data ultimo aggiornamento'] },
|
||
],
|
||
note: 'Esempio prima riga: React | 18.3.1 | MIT | Permissiva | https://react.dev | Frontend UI | Nessuna | N/A | 2026-04-01',
|
||
},
|
||
{
|
||
title: 'Riepilogo',
|
||
content: [
|
||
{ label: 'Totale componenti', fields: ['___'] },
|
||
{ label: 'Componenti con licenze copyleft', fields: ['___ (verificare compatibilità)'] },
|
||
{ label: 'Componenti con vulnerabilità note', fields: ['___ (dettaglio sopra)'] },
|
||
{ label: 'Componenti senza licenza dichiarata', fields: ['___ (da verificare)'] },
|
||
{ label: 'Data generazione SBOM', fields: ['____________'] },
|
||
{ label: 'Generato da', fields: ['[Nome] — [Ruolo]'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'retention',
|
||
heading: 'Policy di retention dei dati',
|
||
description: 'Definisce tempi di conservazione, giustificazioni e modalità di cancellazione per tutte le categorie di dati trattati.',
|
||
sections: [
|
||
{
|
||
title: 'Principi generali',
|
||
content: [
|
||
'I dati personali sono conservati solo per il tempo necessario al raggiungimento delle finalità per cui sono stati raccolti.',
|
||
'Alla scadenza del periodo di retention, i dati sono anonimizzati o cancellati in modo sicuro e irreversibile.',
|
||
'I periodi di retention sono documentati, giustificati e comunicati agli interessati nell’informativa privacy.',
|
||
'La policy è soggetta a revisione almeno annuale o a fronte di modifiche normative.',
|
||
],
|
||
},
|
||
{
|
||
title: 'Tabella dei periodi di retention',
|
||
content: [
|
||
{
|
||
label: 'Dati anagrafici e di contatto',
|
||
fields: ['Periodo: 10 anni dalla cessazione del rapporto (obblighi fiscali e legali). Giustificazione: normativa fiscale thailandese. Cancellazione: anonimizzazione al termine.'],
|
||
},
|
||
{
|
||
label: 'Dati sanitari (MediAura / Health Tech)',
|
||
fields: ['Periodo: durata del rapporto + 10 anni (o come da normativa locale applicabile). Giustificazione: normative sanitarie, contenziosi, esigenze cliniche. Cancellazione: distruzione sicura con certificazione.'],
|
||
},
|
||
{
|
||
label: 'Dati legali / pratiche (LexAura / Legal Tech)',
|
||
fields: ['Periodo: durata del rapporto + 10 anni. Giustificazione: obblighi deontologici forensi, prescrizione, contenziosi. Cancellazione: previa verifica con il titolare dello studio.'],
|
||
},
|
||
{
|
||
label: 'Log di accesso e audit trail',
|
||
fields: ['Periodo: 2 anni. Giustificazione: sicurezza, investigazioni, compliance. Cancellazione: rotazione automatica.'],
|
||
},
|
||
{
|
||
label: 'Dati di fatturazione',
|
||
fields: ['Periodo: 10 anni. Giustificazione: obblighi fiscali e contabili. Cancellazione: anonimizzazione al termine.'],
|
||
},
|
||
{
|
||
label: 'Dati di candidati non assunti',
|
||
fields: ['Periodo: 12 mesi dalla candidatura. Giustificazione: eventuali future opportunità (con consenso). Cancellazione: distruzione al termine.'],
|
||
},
|
||
{
|
||
label: 'Cookie e dati di tracciamento',
|
||
fields: ['Periodo: come da cookie policy (max 12 mesi). Giustificazione: analisi e funzionalità del sito. Cancellazione: scadenza automatica o su richiesta.'],
|
||
},
|
||
{
|
||
label: 'Backup',
|
||
fields: ['Periodo: 30 giorni (backup operativi), 12 mesi (backup storici). Giustificazione: disaster recovery e business continuity. Cancellazione: rotazione automatica. I dati personali contenuti nei backup sono soggetti agli stessi periodi di retention e vengono cancellati dal backup attivo al termine.'],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
title: 'Modalità di cancellazione',
|
||
content: [
|
||
'Cancellazione logica: i dati sono resi inaccessibili all’utente ma conservati in area segregata per il periodo di retention.',
|
||
'Cancellazione fisica: al termine del periodo di retention, i dati sono sovrascritti o distrutti in modo irreversibile (crypto-shredding, degaussing, distruzione fisica per supporti).',
|
||
'Anonimizzazione: i dati sono trasformati in modo irreversibile in forma anonima e non riconducibile all’interessato.',
|
||
'Per ogni cancellazione è prodotta evidenza documentale (log, certificazione).',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'ai-impact',
|
||
heading: 'Template valutazione d’impatto AI/ML',
|
||
description: 'Modello per valutare l’impatto etico, legale e tecnico di sistemi di intelligenza artificiale e machine learning.',
|
||
sections: [
|
||
{
|
||
title: 'Informazioni generali',
|
||
content: [
|
||
{ label: 'Nome del sistema/modello', fields: ['_____________________'] },
|
||
{ label: 'Versione', fields: ['_____________________'] },
|
||
{ label: 'Perimetro', fields: ['[ ] Piattaforma [ ] Legal Tech / LexAura [ ] Health Tech / MediAura'] },
|
||
{ label: 'Responsabile tecnico', fields: ['_____________________'] },
|
||
{ label: 'Data valutazione', fields: ['_____________________'] },
|
||
],
|
||
},
|
||
{
|
||
title: '1. Descrizione del sistema AI',
|
||
content: [
|
||
'Descrivere lo scopo del sistema, le funzionalità, gli utenti target e il contesto d’uso. Specificare se il sistema prende decisioni automatizzate o fornisce raccomandazioni con supervisione umana.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Dataset e provenienza',
|
||
content: [
|
||
{ label: 'Fonti dei dati di training', fields: ['[ ] Dati interni [ ] Dati pubblici [ ] Dati di terze parti [ ] Dati sintetici'] },
|
||
{ label: 'Volume e caratteristiche', fields: ['Numero di record: ___ Features: ___ Bilanciamento classi: ___'] },
|
||
{ label: 'Qualità e limiti noti', fields: ['Descrivere eventuali bias noti, dati mancanti, rumore, qualità della labeling.'] },
|
||
{ label: 'Pre-elaborazione', fields: ['Descrivere pulizia, normalizzazione, feature engineering.'] },
|
||
{ label: 'Conformità privacy', fields: ['[ ] Dati anonimizzati [ ] Consenso ottenuto [ ] DPIA eseguita [ ] Base giuridica documentata'] },
|
||
],
|
||
},
|
||
{
|
||
title: '3. Bias assessment',
|
||
content: [
|
||
'Descrivere le analisi condotte per identificare e mitigare bias (demografici, culturali, di genere, etnici, ecc.).',
|
||
'Indicare metriche di fairness utilizzate e risultati ottenuti.',
|
||
{ label: 'Bias identificati', fields: ['_____________________'] },
|
||
{ label: 'Misure di mitigazione', fields: ['_____________________'] },
|
||
{ label: 'Test di equità superati', fields: ['[ ] Sì [ ] No [ ] Parzialmente — spiegare: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: '4. Supervisione umana',
|
||
content: [
|
||
{ label: 'Livello di automazione', fields: ['[ ] Fully automated [ ] Human-in-the-loop [ ] Human-on-the-loop [ ] Solo raccomandazione'] },
|
||
{ label: 'Meccanismo di override', fields: ['Come l’utente può sovrascrivere la decisione del sistema?'] },
|
||
{ label: 'Avvisi e limitazioni', fields: ['Quali avvisi vengono mostrati all’utente sui limiti del sistema?'] },
|
||
],
|
||
},
|
||
{
|
||
title: '5. Explainability e trasparenza',
|
||
content: [
|
||
{ label: 'Metodo di explainability', fields: ['[ ] SHAP [ ] LIME [ ] Feature importance [ ] Attention maps [ ] Altro: ___'] },
|
||
{ label: 'Documentazione per l’utente', fields: ['Descrivere come vengono spiegate le decisioni all’utente finale.'] },
|
||
{ label: 'Limitazioni comunicate', fields: ['Come sono comunicati limiti, accuratezza e margini di errore?'] },
|
||
],
|
||
},
|
||
{
|
||
title: '6. Monitoraggio post-release',
|
||
content: [
|
||
{ label: 'Metriche monitorate', fields: ['Accuratezza, precision, recall, F1, drift detection, fairness metrics, latenza.'] },
|
||
{ label: 'Frequenza monitoraggio', fields: ['[ ] Continuo [ ] Giornaliero [ ] Settimanale [ ] Mensile'] },
|
||
{ label: 'Alerting', fields: ['Soglie di allarme definite per drift e degrado delle performance.'] },
|
||
{ label: 'Piano di rollback', fields: ['Procedura per disattivare o sostituire il modello in caso di comportamenti inattesi o dannosi.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Valutazione dei rischi',
|
||
content: [
|
||
{ label: 'Impatto su diritti fondamentali', fields: ['[ ] Basso [ ] Medio [ ] Alto — spiegare: ___'] },
|
||
{ label: 'Impatto su salute o sicurezza', fields: ['[ ] Nessuno [ ] Potenziale [ ] Diretto — spiegare: ___'] },
|
||
{ label: 'Rischio di discriminazione', fields: ['[ ] Basso [ ] Medio [ ] Alto — spiegare: ___'] },
|
||
{ label: 'Rischio di opacità', fields: ['[ ] Basso [ ] Medio [ ] Alto — spiegare: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: '8. Approvazione',
|
||
content: [
|
||
{ label: 'Compilatore', fields: ['Nome: ___ Firma: ___ Data: ___'] },
|
||
{ label: 'CTO / Referente tecnico', fields: ['Nome: ___ Firma: ___ Data: ___'] },
|
||
{ label: 'DPO / Referente privacy', fields: ['Nome: ___ Firma: ___ Data: ___'] },
|
||
{ label: 'Legal & Compliance', fields: ['Nome: ___ Firma: ___ Data: ___'] },
|
||
{ label: 'Comitato etico (se applicabile)', fields: ['Parere: ___ Data: ___'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'piano-formazione',
|
||
heading: 'Piano di formazione — onboarding 90 giorni e formazione annuale',
|
||
description: 'Curriculum obbligatorio per collaboratori: moduli, tempistiche, ruoli critici e registro di completamento.',
|
||
intro:
|
||
'Documento operativo collegato alla sezione 13 del Codice Etico. HR è owner; CISO, DPO e Legal forniscono i contenuti di dominio. Conservare le evidenze di completamento nel fascicolo personale.',
|
||
sections: [
|
||
{
|
||
title: '1. Obiettivi',
|
||
content: [
|
||
'Assicurare che ogni collaboratore conosca Codice Etico, obblighi di sicurezza e privacy, e limiti del proprio ruolo sui dati (piattaforma, Legal Tech, Health Tech).',
|
||
'Ridurre il rischio operativo e regolatorio nei primi 90 giorni e mantenere competenze aggiornate con refresh annuale.',
|
||
'Produrre evidenze documentali (attestati, quiz, registro) per audit e KPI di formazione completata.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Destinatari e responsabilità',
|
||
content: [
|
||
{ label: 'Tutti i collaboratori', fields: ['Fondatori, dipendenti, consulenti e appaltatori con accesso a sistemi o dati NexStudio.'] },
|
||
{ label: 'Owner del piano', fields: ['HR (calendario, registro, reminder).'] },
|
||
{ label: 'Owner contenuti', fields: ['CISO (sicurezza), DPO (privacy), Legal (Codice Etico / compliance), CTO (coding sicuro / AI).'] },
|
||
{ label: 'Manager di linea', fields: ['Verificano completamento entro le scadenze e segnalano ritardi a HR.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '3. Moduli obbligatori (core)',
|
||
content: [
|
||
{ label: 'M1 — Codice Etico e condotta', fields: ['Durata: 1,5 h. Contenuti: valori, conflitti di interesse, segnalazioni, sanzioni. Output: dichiarazione di adesione firmata.'] },
|
||
{ label: 'M2 — Sicurezza informatica', fields: ['Durata: 2 h. Contenuti: phishing, password/MFA, classificazione dati, gestione dispositivi, incident reporting. Output: quiz ≥ 80%.'] },
|
||
{ label: 'M3 — Privacy PDPA e GDPR', fields: ['Durata: 2 h. Contenuti: basi giuridiche, diritti interessati, trasferimenti, breach notification 72h, ruoli titolare/responsabile. Output: quiz ≥ 80%.'] },
|
||
{ label: 'M4 — Dati sensibili e perimetri prodotto', fields: ['Durata: 1,5 h. Contenuti: LexAura (segreto professionale), MediAura (dati sanitari), minimizzazione, accessi privilegiati. Output: checklist di comprensione firmata.'] },
|
||
{ label: 'M5 — Uso responsabile di AI/ML', fields: ['Durata: 1,5 h. Contenuti: bias, supervisione umana, limiti del modello, divieto di usi incompatibili. Output: quiz ≥ 80%.'] },
|
||
{ label: 'M6 — Coding sicuro e release (ruoli tecnici)', fields: ['Durata: 2 h. Contenuti: OWASP top risks, secret management, checklist pre-release, SBOM. Obbligatorio per sviluppatori, DevOps, QA. Output: quiz ≥ 80% + esercizio su checklist.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '4. Calendario onboarding 90 giorni',
|
||
content: [
|
||
{ label: 'Giorno 0–7 (settimana 1)', fields: ['M1 Codice Etico + firma adesione e NDA se applicabile. Accesso sistemi solo dopo MFA e briefing sicurezza base (estratto M2).'] },
|
||
{ label: 'Giorno 8–30 (mese 1)', fields: ['M2 Sicurezza completo + M3 Privacy. Nessun accesso a dati di produzione senza M2/M3 completati.'] },
|
||
{ label: 'Giorno 31–60 (mese 2)', fields: ['M4 Perimetri prodotto (LexAura/MediAura secondo ruolo) + M5 AI. Ruoli tecnici: avvio M6.'] },
|
||
{ label: 'Giorno 61–90 (mese 3)', fields: ['Completamento M6 (se dovuto). Review con manager: gap, formazione aggiuntiva, conferma registro. Checkpoint HR: 100% moduli obbligatori del ruolo.'] },
|
||
],
|
||
note: 'Scadenze hard: adesione entro 7 giorni; core M2–M5 entro 60 giorni; M6 entro 90 giorni per i ruoli tecnici. Ritardi > 14 giorni: escalation a HR e manager, possibile limitazione accessi.',
|
||
},
|
||
{
|
||
title: '5. Formazione annuale ricorrente',
|
||
content: [
|
||
'Refresh obbligatorio entro 12 mesi dal completamento precedente (o dalla data di onboarding).',
|
||
'Durata minima aggregata: 3 ore (M1 aggiornato + M2/M3 delta normativi + richiamo AI).',
|
||
'Trigger aggiuntivi: cambio normativo rilevante, incidente grave, nuovo perimetro prodotto, cambio ruolo critico.',
|
||
'Formato ammesso: sessione live, e-learning asincrono con quiz, o workshop interno documentato.',
|
||
],
|
||
},
|
||
{
|
||
title: '6. Formazione aggiuntiva per ruoli critici',
|
||
content: [
|
||
{ label: 'CISO / security', fields: ['Incident response playbook, tabletop annuale, threat modeling.'] },
|
||
{ label: 'DPO / privacy', fields: ['DPIA workshop, diritti interessati, trasferimenti internazionali.'] },
|
||
{ label: 'Legal & compliance', fields: ['Aggiornamenti regolatori LexAura/MediAura, contratti sub-processori.'] },
|
||
{ label: 'Sviluppo / DevOps', fields: ['Secure SDLC avanzato, review SBOM, penetration test findings walkthrough.'] },
|
||
{ label: 'Supporto / customer success', fields: ['Accesso minimo ai dati cliente, script di escalation, divieto di uso fuori ticket.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Modalità di erogazione e materiali',
|
||
content: [
|
||
'Lingue: italiano, inglese, thailandese (allineate al sito e al Codice Etico).',
|
||
'Materiali: slide/video interni, Codice Etico vigente, allegati operativi (checklist, DPIA, AI impact).',
|
||
'Valutazione: quiz a risposta multipla (soglia 80%) o attestato di presenza + exercise per workshop.',
|
||
'Ripetizione: in caso di quiz insufficiente, ritentativo entro 14 giorni con tutoring del owner di dominio.',
|
||
],
|
||
},
|
||
{
|
||
title: '8. Registro formazione (template riga)',
|
||
content: [
|
||
{
|
||
label: 'Campi obbligatori per ogni record',
|
||
fields: [
|
||
'Nome collaboratore',
|
||
'Ruolo',
|
||
'Modulo (M1–M6 / annuale / critico)',
|
||
'Data',
|
||
'Durata (h)',
|
||
'Esito (superato / da ripetere)',
|
||
'Evidenza (link quiz / PDF / firma)',
|
||
'Owner verifica',
|
||
],
|
||
},
|
||
],
|
||
note: 'Retention del registro: allineata alla policy retention (record di formazione e dichiarazioni di adesione). Formato consigliato: foglio condiviso o HRIS con export per audit.',
|
||
},
|
||
{
|
||
title: '9. KPI e controllo',
|
||
content: [
|
||
'% onboarding con moduli obbligatori completati entro 90 giorni (target ≥ 95%).',
|
||
'% personale con refresh annuale in regola (target ≥ 95%).',
|
||
'Tempo medio di completamento M1–M5.',
|
||
'Numero ritardi > 14 giorni e azioni correttive.',
|
||
],
|
||
},
|
||
],
|
||
footer: 'Approvazione piano: HR _______ · CISO _______ · DPO _______ · Data _______',
|
||
},
|
||
{
|
||
id: 'security-disclosure',
|
||
heading: 'Policy di responsible disclosure e segnalazione vulnerabilità',
|
||
description: 'Come segnalare vulnerabilità di sicurezza a NexStudio: canale, tempi di risposta, ambito e regole di buon senso (bug bounty soft).',
|
||
intro:
|
||
'Documento operativo collegato alla sezione 11 del Codice Etico (gestione vulnerabilità). Canale ufficiale: security@nexstudio.com. Un programma di bug bounty a premi monetari potrà essere aggiunto in seguito senza cambiare questo canale.',
|
||
sections: [
|
||
{
|
||
title: '1. Scopo',
|
||
content: [
|
||
'Consentire a ricercatori e utenti di segnalare vulnerabilità in buona fede, con tempi di risposta definiti e senza rischio di azioni legali se rispettano questa policy.',
|
||
'Proteggere i dati di clienti, pazienti e studi (LexAura / MediAura) e la disponibilità dei servizi SaaS.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Ambito (in scope)',
|
||
content: [
|
||
'Siti e app web pubblici NexStudio (dominio principale e sottopagine IT/EN/TH).',
|
||
'API e endpoint autenticati dei prodotti LexAura e MediAura esposti in produzione o staging pubblico.',
|
||
'Infrastruttura cloud direttamente attribuibile a NexStudio e raggiungibile da Internet.',
|
||
'Errori di configurazione che espongono dati personali, segreti, backup o pannelli di amministrazione.',
|
||
],
|
||
},
|
||
{
|
||
title: '3. Fuori ambito (out of scope)',
|
||
content: [
|
||
'Attacchi DoS/DDoS, flood, stress test non concordati.',
|
||
'Social engineering verso dipendenti, clienti o fornitori (phishing, pretexting).',
|
||
'Spam, malware delivery, physical security.',
|
||
'Vulnerabilità su prodotti di terze parti non gestiti da NexStudio, salvo misconfigurazione nostra.',
|
||
'Report generati solo da scanner automatici senza PoC riproducibile.',
|
||
'Finding già noti e in remediation (verificare risposta automatica o stato pubblico se disponibile).',
|
||
],
|
||
},
|
||
{
|
||
title: '4. Regole di test in buona fede',
|
||
content: [
|
||
'Non accedere, modificare o cancellare dati di terzi oltre lo stretto necessario per dimostrare il problema.',
|
||
'Fermarsi immediatamente se si incontrano dati personali o sanitari reali; segnalare senza exfiltrare.',
|
||
'Non eseguire exploit che degradino il servizio o compromettano altri utenti.',
|
||
'Non richiedere riscatto o divulgare pubblicamente prima della coordinazione (embargo ragionevole).',
|
||
'Usare account di test propri o ambienti staging quando disponibili.',
|
||
],
|
||
},
|
||
{
|
||
title: '5. Come segnalare',
|
||
content: [
|
||
{ label: 'Canale', fields: ['Email: security@nexstudio.com (PGP opzionale, se pubblicato in seguito).'] },
|
||
{
|
||
label: 'Contenuto minimo della segnalazione',
|
||
fields: [
|
||
'Titolo sintetico',
|
||
'URL / endpoint / componente',
|
||
'Descrizione e impatto',
|
||
'Passi per riprodurre (PoC)',
|
||
'Severità stimata (Low/Medium/High/Critical)',
|
||
'Contatto per follow-up',
|
||
'Se i dati sono stati visti: categorie e volume (senza allegare i dati stessi)',
|
||
],
|
||
},
|
||
],
|
||
note: 'Oggetto consigliato: [SECURITY] breve titolo. Non allegare dump di dati reali.',
|
||
},
|
||
{
|
||
title: '6. SLA di risposta e remediation',
|
||
content: [
|
||
{ label: 'Ack (ricezione)', fields: ['Entro 72 ore lavorative dalla segnalazione valida.'] },
|
||
{ label: 'Triage iniziale', fields: ['Entro 5 giorni lavorativi: conferma in/out of scope e severità preliminare.'] },
|
||
{
|
||
label: 'Target di fix (indicativi)',
|
||
fields: [
|
||
'Critical: contenimento immediato; fix o mitigazione entro 7 giorni',
|
||
'High: 14 giorni',
|
||
'Medium: 30 giorni',
|
||
'Low: 90 giorni o prossimo ciclo di release',
|
||
],
|
||
},
|
||
{ label: 'Comunicazione', fields: ['Aggiornamenti al reporter fino a chiusura; eventuale advisory pubblico dopo fix, con credito se richiesto.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Safe harbor',
|
||
content: [
|
||
'NexStudio non avvierà azioni legali contro chi segnala in buona fede rispettando questa policy e le leggi applicabili.',
|
||
'La safe harbor non copre attività fuori ambito, furto di dati, estorsione o danni intenzionali.',
|
||
],
|
||
},
|
||
{
|
||
title: '8. Riconoscimenti e bug bounty',
|
||
content: [
|
||
'Fase attuale (soft bounty): ringraziamento scritto e, se il reporter acconsente, menzione in hall of fame / advisory.',
|
||
'Premi monetari o swag: non garantiti; potranno essere introdotti con griglia pubblica senza cambiare il canale security@.',
|
||
'Duplicati e out-of-scope: ack cortese senza reward.',
|
||
],
|
||
},
|
||
{
|
||
title: '9. Owner interni',
|
||
content: [
|
||
{ label: 'CISO / Security', fields: ['Triage, remediation, comunicazione al reporter.'] },
|
||
{ label: 'DPO', fields: ['Coinvolto se la vulnerabilità implica dati personali o breach.'] },
|
||
{ label: 'Legal', fields: ['Valutazione safe harbor e disclosure pubblica.'] },
|
||
{ label: 'CTO', fields: ['Priorità tecnica e risorse di fix.'] },
|
||
],
|
||
},
|
||
],
|
||
footer: 'Approvazione policy: CISO _______ · CTO _______ · Legal _______ · Data _______',
|
||
},
|
||
],
|
||
},
|
||
en: {
|
||
page: {
|
||
title: 'Code of Ethics Annexes — NexStudio',
|
||
description: 'Operational templates annexed to the NexStudio Code of Ethics: adhesion, NDA, checklist, DPIA, privacy, SBOM, retention, AI impact, training plan, responsible disclosure.',
|
||
heading: 'Annexes and operational forms',
|
||
lead: 'Complementary documents to the Code of Ethics. Each annex is a template to be customized and adopted according to operational needs.',
|
||
backLabel: '← Back to Code of Ethics',
|
||
},
|
||
allegati: [
|
||
{
|
||
id: 'adesione',
|
||
heading: 'Personal declaration of adhesion to the Code of Ethics',
|
||
description: 'Form to be signed by every collaborator during onboarding.',
|
||
intro: 'To be filled in, signed and kept in the personnel file.',
|
||
sections: [
|
||
{
|
||
content: [
|
||
{ label: 'Full name', fields: ['_____________________________'] },
|
||
{ label: 'Role / title', fields: ['_____________________________'] },
|
||
{ label: 'Onboarding date', fields: ['_____________________________'] },
|
||
{ label: 'Signature', fields: ['_____________________________'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Declaration',
|
||
intro: 'The undersigned declares:',
|
||
content: [
|
||
'To have received, read and understood the NexStudio Code of Ethics in its current version.',
|
||
'To commit to respecting its principles, rules of conduct and procedures.',
|
||
'To have received or to receive according to the training plan the mandatory training on information security, privacy (PDPA and GDPR), sensitive data handling, responsible AI use and secure coding practices.',
|
||
'To commit to reporting, in good faith and through the designated channels, any violations of the Code of which they become aware.',
|
||
'To be aware that violation of the Code may result in proportionate disciplinary measures, up to termination of the contractual relationship.',
|
||
'To accept that this declaration will be kept in their personnel file and used for corporate governance purposes.',
|
||
],
|
||
},
|
||
],
|
||
footer: 'Place and date: _____________________ · Signature: _____________________',
|
||
},
|
||
{
|
||
id: 'nda',
|
||
heading: 'NDA template and minimum clauses for vendors and sub-processors',
|
||
description: 'Standard confidentiality agreement for external collaborators, consultants, vendors and sub-processors.',
|
||
intro: 'This template defines the minimum confidentiality clauses. Adapt the introductory part (parties, subject matter, duration) to the specific relationship.',
|
||
sections: [
|
||
{
|
||
title: '1. Definition of Confidential Information',
|
||
content: [
|
||
'"Confidential Information" means any data, information, document, know-how, source code, technical specification, business strategy, personal or sensitive data, communication or material — in any form (written, oral, electronic, visual) — that one party (the "Disclosing Party") communicates to the other (the "Receiving Party") in relation to the subject matter of the relationship, regardless of whether it is expressly marked as confidential.',
|
||
'Confidential Information also includes personal data processed on behalf of the Controller, data relating to patients, clients and care recipients (for the Legal Tech and Health Tech perimeters), system logs, credentials and test and audit results.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Obligations of the Receiving Party',
|
||
content: [
|
||
'Use Confidential Information exclusively for the agreed purposes and for the performance of the contractual relationship.',
|
||
'Not disclose, copy, reproduce or distribute Confidential Information to third parties without prior written authorization from the Disclosing Party.',
|
||
'Limit access to Confidential Information only to authorized persons who need to know and who are bound by confidentiality obligations at least equivalent.',
|
||
'Adopt adequate technical and organizational security measures to protect Confidential Information from unauthorized access, loss, theft or disclosure.',
|
||
'In case of sub-processing, request prior written authorization and impose equivalent contractual obligations on the sub-processor.',
|
||
],
|
||
},
|
||
{
|
||
title: '3. Exclusions',
|
||
content: [
|
||
'Information already in the public domain without breach of this agreement.',
|
||
'Information already in the Receiving Party\'s possession before disclosure, as documented.',
|
||
'Information legitimately received from third parties without confidentiality obligations.',
|
||
'Information that the Receiving Party is required to disclose by law or authority order (with prior notice to the Disclosing Party, where permitted).',
|
||
],
|
||
},
|
||
{
|
||
title: '4. Breach Notification',
|
||
content: [
|
||
'The Receiving Party must notify the Disclosing Party of any unauthorized access, loss or disclosure of Confidential Information within 24 hours of discovery, providing: description of the event, data and categories of data involved, measures taken or proposed to mitigate the effects, contact point for information.',
|
||
],
|
||
},
|
||
{
|
||
title: '5. Duration and return',
|
||
content: [
|
||
'The confidentiality obligation lasts for the entire duration of the relationship and for 5 years after its termination, unless longer legal obligations apply.',
|
||
'Upon termination of the relationship, the Receiving Party must return or destroy all Confidential Information, providing written attestation.',
|
||
],
|
||
},
|
||
{
|
||
title: '6. Equivalent security measures',
|
||
content: [
|
||
'Encryption at rest and in transit with up-to-date algorithms (minimum AES-256, TLS 1.3).',
|
||
'Access control with least-privilege principle and mandatory MFA.',
|
||
'Immutable logging for access to sensitive data.',
|
||
'Documented incident management procedures.',
|
||
'Staff training on security and privacy.',
|
||
],
|
||
},
|
||
{
|
||
title: '7. Governing law and jurisdiction',
|
||
content: [
|
||
'Thai law, with possible reference to GDPR/PDPA clauses for personal data processing. Competent court: Bangkok, Thailand, unless otherwise agreed in writing.',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'checklist-prerelease',
|
||
heading: 'Pre-release checklist — Security & Privacy',
|
||
description: 'Mandatory checklist before every production release.',
|
||
intro: 'To be completed by the development team and validated by the CISO/security lead. Each item must receive a check (✓), N/A (not applicable) or ✗ with note.',
|
||
sections: [
|
||
{
|
||
title: 'Security',
|
||
content: [
|
||
{ label: 'Code review completed and approved', fields: ['[ ]'] },
|
||
{ label: 'Automated tests passed (green CI)', fields: ['[ ]'] },
|
||
{ label: 'Static code analysis (SAST) with no critical or high vulnerabilities', fields: ['[ ]'] },
|
||
{ label: 'Dependency scan (SCA) with no known vulnerabilities with CVSS ≥ 7', fields: ['[ ]'] },
|
||
{ label: 'Penetration test or dynamic scan (DAST) performed on pre-release build', fields: ['[ ]'] },
|
||
{ label: 'No hardcoded credentials, tokens or secrets in the codebase', fields: ['[ ]'] },
|
||
{ label: 'HTTP security headers configured (HSTS, CSP, X-Frame-Options, etc.)', fields: ['[ ]'] },
|
||
{ label: 'CORS configured correctly (no wildcard on sensitive origins)', fields: ['[ ]'] },
|
||
{ label: 'Rate limiting active on public endpoints', fields: ['[ ]'] },
|
||
{ label: 'Dependencies updated to the latest stable version (or security patches applied)', fields: ['[ ]'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Privacy and data',
|
||
content: [
|
||
{ label: 'No real personal data in test environments (only synthetic/anonymized data)', fields: ['[ ]'] },
|
||
{ label: 'Encryption at rest enabled for all sensitive data', fields: ['[ ]'] },
|
||
{ label: 'Encryption in transit (TLS 1.3) active on all endpoints', fields: ['[ ]'] },
|
||
{ label: 'Logging free of personal or sensitive data in cleartext', fields: ['[ ]'] },
|
||
{ label: 'Consent mechanisms verifiable and recorded (if applicable)', fields: ['[ ]'] },
|
||
{ label: 'Deletion/right to erasure procedures tested and working', fields: ['[ ]'] },
|
||
{ label: 'Retention policy implemented and verified', fields: ['[ ]'] },
|
||
{ label: 'DPIA updated for processing activities involved in the release', fields: ['[ ]'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Operations',
|
||
content: [
|
||
{ label: 'Rollback plan documented and tested', fields: ['[ ]'] },
|
||
{ label: 'Changelog compiled with known impacts', fields: ['[ ]'] },
|
||
{ label: 'Notification to internal stakeholders (support, security, DPO)', fields: ['[ ]'] },
|
||
{ label: 'Monitoring and alerting configured for new features', fields: ['[ ]'] },
|
||
],
|
||
note: 'Signatures: Developer _______ Reviewer _______ CISO/DPO _______ Date _______',
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'incident-management',
|
||
heading: 'Incident management — Flowchart and notification template',
|
||
description: 'Operating procedure and communication template for managing security incidents and data breaches.',
|
||
sections: [
|
||
{
|
||
title: 'Flowchart: incident management phases',
|
||
content: [
|
||
'1. DETECTION — The incident is detected by: automatic monitoring system, internal report, bug bounty/external reporter, notification from a vendor or partner.',
|
||
'2. TRIAGE AND CLASSIFICATION (max 1 hour) — The security team assesses: incident type (data breach, unauthorized access, malware, DDoS, etc.), severity (low/medium/high/critical), perimeter involved (platform, Legal Tech, Health Tech), data involved (personal, sensitive, health, legal).',
|
||
'3. CONTAINMENT (immediate) — Isolate compromised systems, revoke exposed credentials or tokens, block malicious IPs or accounts, activate the designated response team.',
|
||
'4. ERADICATION — Remove root cause (patch, reconfiguration, malware removal), verify no backdoors or persistence, document actions taken.',
|
||
'5. RECOVERY — Restore systems from clean backups, apply patches and mitigations, validate operation in an isolated environment before returning to production.',
|
||
'6. NOTIFICATION — Within 72 hours of discovery: notify DPO and Legal & Compliance; if personal data breach, assess obligation to notify authority (PDPA/GDPR) and data subjects. Use the notification template (see below).',
|
||
'7. POST-MORTEM (within 5 working days) — Root cause analysis, lessons learned, security playbook and controls update, internal communication (non-blaming).',
|
||
],
|
||
},
|
||
{
|
||
title: 'Incident notification template',
|
||
intro: 'To be sent internally and, if required, externally.',
|
||
content: [
|
||
{ label: 'Incident ID', fields: ['INC-YYYY-NNN'] },
|
||
{ label: 'Detection date and time', fields: ['_____________________'] },
|
||
{ label: 'Containment date and time', fields: ['_____________________'] },
|
||
{ label: 'Severity', fields: ['[ ] Low [ ] Medium [ ] High [ ] Critical'] },
|
||
{ label: 'Type', fields: ['[ ] Data breach [ ] Unauthorized access [ ] Malware [ ] DDoS [ ] Other: ___'] },
|
||
{ label: 'Perimeter', fields: ['[ ] Platform [ ] Legal Tech / LexAura [ ] Health Tech / MediAura'] },
|
||
{ label: 'Systems involved', fields: ['_____________________'] },
|
||
{ label: 'Data involved', fields: ['Categories: ___ Estimated data subjects: ___'] },
|
||
{ label: 'Description', fields: ['_____________________'] },
|
||
{ label: 'Actions taken', fields: ['_____________________'] },
|
||
{ label: 'Measures for data subjects', fields: ['_____________________'] },
|
||
{ label: 'Contact point', fields: ['Name: ___ Email: ___ Phone: ___'] },
|
||
{ label: 'Compiled by', fields: ['_____________________'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'dpia',
|
||
heading: 'Simplified DPIA model and completed example',
|
||
description: 'Data Protection Impact Assessment — basic model compliant with PDPA and GDPR.',
|
||
sections: [
|
||
{
|
||
title: 'DPIA model — Required sections',
|
||
content: [
|
||
{ label: '1. Processing title', fields: ['Brief description of the processing under assessment.'] },
|
||
{ label: '2. Controller and processors', fields: ['Controller: ___ Processor(s): ___ Sub-processors: ___ DPO: ___'] },
|
||
{ label: '3. Purpose of processing', fields: ['Describe why the data is processed, legal basis and necessity.'] },
|
||
{ label: '4. Data categories', fields: ['[ ] Regular personal [ ] Special categories (health, legal, biometric) [ ] Criminal'] },
|
||
{ label: '5. Data subject categories', fields: ['[ ] Patients [ ] Firm clients [ ] Employees [ ] Platform users [ ] Other: ___'] },
|
||
{ label: '6. Processing operations', fields: ['Collection, recording, organization, storage, consultation, disclosure, erasure, etc.'] },
|
||
{ label: '7. Technologies used', fields: ['Database, cloud, API, AI/ML, etc.'] },
|
||
{ label: '8. Risk assessment', fields: ['Likelihood × Impact for each identified risk. Risk mitigation measures planned.'] },
|
||
{ label: '9. Security measures', fields: ['Encryption, access control, logging, backup, etc.'] },
|
||
{ label: '10. DPO consultation', fields: ['DPO opinion: ___ Date: ___'] },
|
||
{ label: '11. Final decision', fields: ['[ ] Acceptable risk [ ] Risk mitigated [ ] Authority consultation needed [ ] Processing not to start'] },
|
||
{ label: '12. Date and signatures', fields: ['Compiler: ___ DPO: ___ Controller: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Completed example — MediAura: clinical data management in the cloud',
|
||
content: [
|
||
{ label: '1. Title', fields: ['Management and storage of clinical patient data on the MediAura platform (cloud, Bangkok).'] },
|
||
{ label: '2. Controller and processors', fields: ['Controller: subscribing medical practice/clinic. Processor: NexStudio. Sub-processors: ISO 27001 certified cloud provider.'] },
|
||
{ label: '3. Purpose', fields: ['Storage and consultation of clinical data to support medical practice. Legal basis: contract performance and patient consent (signed notice).'] },
|
||
{ label: '4. Data categories', fields: ['Special categories: health data (diagnoses, prescriptions, reports). Regular personal: identity, contact details.'] },
|
||
{ label: '5. Data subjects', fields: ['Patients (adults and minors via guardians).'] },
|
||
{ label: '6. Operations', fields: ['Collection, recording, organization, storage, consultation by authorized staff, erasure on request.'] },
|
||
{ label: '7. Technologies', fields: ['Encrypted database (AES-256), REST API with TLS 1.3, AI for clinical suggestions (human supervision mandatory).'] },
|
||
{ label: '8. Risks', fields: ['Unauthorized access to health data (low likelihood, high impact → mitigated with MFA, encryption and audit log). Data loss (low likelihood, critical impact → mitigated with daily backups, tested disaster recovery).'] },
|
||
{ label: '9. Security measures', fields: ['Encryption at rest AES-256 and in transit TLS 1.3. Mandatory MFA. Immutable logs. Automatic daily backup. Quarterly restore test.'] },
|
||
{ label: '10. DPO', fields: ['Favorable opinion with recommendation for annual audit.'] },
|
||
{ label: '11. Decision', fields: ['Risk mitigated — processing approved with annual review.'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'privacy-notice',
|
||
heading: 'Privacy notice model and consent form',
|
||
description: 'Privacy notice template compliant with PDPA and GDPR, with integrated consent form.',
|
||
sections: [
|
||
{
|
||
title: 'Personal data processing notice',
|
||
intro: 'Pursuant to PDPA (Thailand) and, where applicable, GDPR (EU).',
|
||
content: [
|
||
{ label: 'Data Controller', fields: ['[Firm/organization name], with office at [address], email: [___], phone: [___].'] },
|
||
{ label: 'Data Processor (platform provider)', fields: ['NexStudio, Bangkok, Thailand, email: privacy@nexstudio.com.'] },
|
||
{ label: 'Processing purposes', fields: ['Management of [legal/healthcare] services, document archiving, service-related communications, legal obligations.'] },
|
||
{ label: 'Legal basis', fields: ['[Data subject consent / Contract performance / Legal obligation / Legitimate interest].'] },
|
||
{ label: 'Data categories', fields: ['Identity and contact data. [Legal/healthcare] practice-related data. [If healthcare: health data pursuant to Art. 9 GDPR / PDPA].'] },
|
||
{ label: 'Retention period', fields: ['[X years] from the end of the relationship or as provided by the retention policy.'] },
|
||
{ label: 'Data recipients', fields: ['Authorized staff of the Controller. NexStudio (data processor). Cloud service providers (sub-processors with contractual guarantees). Public authorities, if required by law.'] },
|
||
{ label: 'International transfers', fields: ['[Describe if data is transferred outside Thailand/EU and on what legal basis].'] },
|
||
{ label: 'Data subject rights', fields: ['Access, rectification, erasure, restriction, portability, objection, consent withdrawal. To exercise rights, contact the Controller at the above address.'] },
|
||
{ label: 'Complaints', fields: ['The data subject has the right to lodge a complaint with the competent supervisory authority (PDPC in Thailand / Data Protection Authority in the EU).'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'Consent form',
|
||
intro: 'To be filled in and signed by the data subject.',
|
||
content: [
|
||
'I, the undersigned _____________________, born on ____________,',
|
||
'declare that I have received and read the personal data processing notice.',
|
||
'',
|
||
'[ ] I consent to the processing of my personal data for the purposes indicated in the notice.',
|
||
'[ ] I consent to the processing of my special category data (e.g. health data / legal data) for the purposes indicated.',
|
||
'[ ] I consent to the disclosure of my data to the parties indicated in the notice.',
|
||
'',
|
||
'Date: ____________ Signature: _____________________',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'sbom',
|
||
heading: 'SBOM template — Software Bill of Materials',
|
||
description: 'Inventory of software components, licenses and vulnerabilities, in readable format.',
|
||
sections: [
|
||
{
|
||
title: 'Instructions',
|
||
intro: 'Fill in for each open source or third-party component used in the product. Update at every release.',
|
||
content: [
|
||
'Generate automatically with tools such as: CycloneDX, SPDX, Syft, Trivy, OWASP Dependency-Track.',
|
||
'The recommended format is CycloneDX JSON or SPDX tag-value.',
|
||
'Below the template in tabular format for manual review.',
|
||
],
|
||
},
|
||
{
|
||
title: 'Component inventory',
|
||
content: [
|
||
{ label: 'Component name', fields: ['Version', 'License', 'License type (copyleft/permissive)', 'Vendor/URL', 'Usage in product', 'Known vulnerabilities (CVE)', 'CVSS score', 'Last update date'] },
|
||
],
|
||
note: 'Example first row: React | 18.3.1 | MIT | Permissive | https://react.dev | Frontend UI | None | N/A | 2026-04-01',
|
||
},
|
||
{
|
||
title: 'Summary',
|
||
content: [
|
||
{ label: 'Total components', fields: ['___'] },
|
||
{ label: 'Components with copyleft licenses', fields: ['___ (verify compatibility)'] },
|
||
{ label: 'Components with known vulnerabilities', fields: ['___ (details above)'] },
|
||
{ label: 'Components without declared license', fields: ['___ (to be verified)'] },
|
||
{ label: 'SBOM generation date', fields: ['____________'] },
|
||
{ label: 'Generated by', fields: ['[Name] — [Role]'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'retention',
|
||
heading: 'Data retention policy',
|
||
description: 'Defines retention periods, justifications and deletion methods for all categories of data processed.',
|
||
sections: [
|
||
{
|
||
title: 'General principles',
|
||
content: [
|
||
'Personal data is retained only for the time necessary to achieve the purposes for which it was collected.',
|
||
'At the end of the retention period, data is anonymized or securely and irreversibly deleted.',
|
||
'Retention periods are documented, justified and communicated to data subjects in the privacy notice.',
|
||
'The policy is subject to review at least annually or upon regulatory changes.',
|
||
],
|
||
},
|
||
{
|
||
title: 'Retention periods table',
|
||
content: [
|
||
{
|
||
label: 'Identity and contact data',
|
||
fields: ['Period: 10 years from the end of the relationship (tax and legal obligations). Justification: Thai tax regulations. Deletion: anonymization at expiry.'],
|
||
},
|
||
{
|
||
label: 'Health data (MediAura / Health Tech)',
|
||
fields: ['Period: relationship duration + 10 years (or as per applicable local regulations). Justification: healthcare regulations, litigation, clinical needs. Deletion: secure destruction with certification.'],
|
||
},
|
||
{
|
||
label: 'Legal data / case files (LexAura / Legal Tech)',
|
||
fields: ['Period: relationship duration + 10 years. Justification: professional legal obligations, statute of limitations, litigation. Deletion: after verification with the firm controller.'],
|
||
},
|
||
{
|
||
label: 'Access logs and audit trail',
|
||
fields: ['Period: 2 years. Justification: security, investigations, compliance. Deletion: automatic rotation.'],
|
||
},
|
||
{
|
||
label: 'Billing data',
|
||
fields: ['Period: 10 years. Justification: tax and accounting obligations. Deletion: anonymization at expiry.'],
|
||
},
|
||
{
|
||
label: 'Data of non-hired candidates',
|
||
fields: ['Period: 12 months from application. Justification: possible future opportunities (with consent). Deletion: destruction at expiry.'],
|
||
},
|
||
{
|
||
label: 'Cookies and tracking data',
|
||
fields: ['Period: as per cookie policy (max 12 months). Justification: website analysis and functionality. Deletion: automatic expiry or on request.'],
|
||
},
|
||
{
|
||
label: 'Backups',
|
||
fields: ['Period: 30 days (operational backups), 12 months (historical backups). Justification: disaster recovery and business continuity. Deletion: automatic rotation. Personal data contained in backups is subject to the same retention periods and is deleted from the active backup at expiry.'],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
title: 'Deletion methods',
|
||
content: [
|
||
'Logical deletion: data is made inaccessible to the user but retained in a segregated area for the retention period.',
|
||
'Physical deletion: at the end of the retention period, data is irreversibly overwritten or destroyed (crypto-shredding, degaussing, physical destruction for media).',
|
||
'Anonymization: data is irreversibly transformed into anonymous form, not attributable to the data subject.',
|
||
'For each deletion, documentary evidence is produced (log, certification).',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'ai-impact',
|
||
heading: 'AI/ML impact assessment template',
|
||
description: 'Model for assessing the ethical, legal and technical impact of artificial intelligence and machine learning systems.',
|
||
sections: [
|
||
{
|
||
title: 'General information',
|
||
content: [
|
||
{ label: 'System/model name', fields: ['_____________________'] },
|
||
{ label: 'Version', fields: ['_____________________'] },
|
||
{ label: 'Perimeter', fields: ['[ ] Platform [ ] Legal Tech / LexAura [ ] Health Tech / MediAura'] },
|
||
{ label: 'Technical owner', fields: ['_____________________'] },
|
||
{ label: 'Assessment date', fields: ['_____________________'] },
|
||
],
|
||
},
|
||
{
|
||
title: '1. AI system description',
|
||
content: [
|
||
'Describe the system purpose, functionalities, target users and context of use. Specify whether the system makes automated decisions or provides recommendations with human oversight.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Dataset and provenance',
|
||
content: [
|
||
{ label: 'Training data sources', fields: ['[ ] Internal data [ ] Public data [ ] Third-party data [ ] Synthetic data'] },
|
||
{ label: 'Volume and characteristics', fields: ['Number of records: ___ Features: ___ Class balance: ___'] },
|
||
{ label: 'Quality and known limits', fields: ['Describe any known bias, missing data, noise, labeling quality.'] },
|
||
{ label: 'Pre-processing', fields: ['Describe cleaning, normalization, feature engineering.'] },
|
||
{ label: 'Privacy compliance', fields: ['[ ] Anonymized data [ ] Consent obtained [ ] DPIA executed [ ] Legal basis documented'] },
|
||
],
|
||
},
|
||
{
|
||
title: '3. Bias assessment',
|
||
content: [
|
||
'Describe the analyses conducted to identify and mitigate bias (demographic, cultural, gender, ethnic, etc.).',
|
||
'Indicate fairness metrics used and results obtained.',
|
||
{ label: 'Bias identified', fields: ['_____________________'] },
|
||
{ label: 'Mitigation measures', fields: ['_____________________'] },
|
||
{ label: 'Fairness tests passed', fields: ['[ ] Yes [ ] No [ ] Partially — explain: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: '4. Human oversight',
|
||
content: [
|
||
{ label: 'Automation level', fields: ['[ ] Fully automated [ ] Human-in-the-loop [ ] Human-on-the-loop [ ] Recommendation only'] },
|
||
{ label: 'Override mechanism', fields: ['How can the user override the system\'s decision?'] },
|
||
{ label: 'Warnings and limitations', fields: ['What warnings are shown to the user about the system\'s limits?'] },
|
||
],
|
||
},
|
||
{
|
||
title: '5. Explainability and transparency',
|
||
content: [
|
||
{ label: 'Explainability method', fields: ['[ ] SHAP [ ] LIME [ ] Feature importance [ ] Attention maps [ ] Other: ___'] },
|
||
{ label: 'User documentation', fields: ['Describe how decisions are explained to the end user.'] },
|
||
{ label: 'Limitations communicated', fields: ['How are limits, accuracy and error margins communicated?'] },
|
||
],
|
||
},
|
||
{
|
||
title: '6. Post-release monitoring',
|
||
content: [
|
||
{ label: 'Metrics monitored', fields: ['Accuracy, precision, recall, F1, drift detection, fairness metrics, latency.'] },
|
||
{ label: 'Monitoring frequency', fields: ['[ ] Continuous [ ] Daily [ ] Weekly [ ] Monthly'] },
|
||
{ label: 'Alerting', fields: ['Alert thresholds defined for drift and performance degradation.'] },
|
||
{ label: 'Rollback plan', fields: ['Procedure to deactivate or replace the model in case of unexpected or harmful behavior.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Risk assessment',
|
||
content: [
|
||
{ label: 'Impact on fundamental rights', fields: ['[ ] Low [ ] Medium [ ] High — explain: ___'] },
|
||
{ label: 'Impact on health or safety', fields: ['[ ] None [ ] Potential [ ] Direct — explain: ___'] },
|
||
{ label: 'Discrimination risk', fields: ['[ ] Low [ ] Medium [ ] High — explain: ___'] },
|
||
{ label: 'Opacity risk', fields: ['[ ] Low [ ] Medium [ ] High — explain: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: '8. Approval',
|
||
content: [
|
||
{ label: 'Compiler', fields: ['Name: ___ Signature: ___ Date: ___'] },
|
||
{ label: 'CTO / Technical lead', fields: ['Name: ___ Signature: ___ Date: ___'] },
|
||
{ label: 'DPO / Privacy lead', fields: ['Name: ___ Signature: ___ Date: ___'] },
|
||
{ label: 'Legal & Compliance', fields: ['Name: ___ Signature: ___ Date: ___'] },
|
||
{ label: 'Ethics committee (if applicable)', fields: ['Opinion: ___ Date: ___'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'piano-formazione',
|
||
heading: 'Training plan — 90-day onboarding and annual refresh',
|
||
description: 'Mandatory curriculum for collaborators: modules, timelines, critical roles and completion register.',
|
||
intro:
|
||
'Operational document linked to section 13 of the Code of Ethics. HR owns the plan; CISO, DPO and Legal provide domain content. Keep completion evidence in the personnel file.',
|
||
sections: [
|
||
{
|
||
title: '1. Objectives',
|
||
content: [
|
||
'Ensure every collaborator knows the Code of Ethics, security and privacy duties, and role limits on data (platform, Legal Tech, Health Tech).',
|
||
'Reduce operational and regulatory risk in the first 90 days and keep skills current with an annual refresh.',
|
||
'Produce documentary evidence (attestations, quizzes, register) for audits and training-completion KPIs.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Audience and responsibilities',
|
||
content: [
|
||
{ label: 'All collaborators', fields: ['Founders, employees, consultants and contractors with access to NexStudio systems or data.'] },
|
||
{ label: 'Plan owner', fields: ['HR (calendar, register, reminders).'] },
|
||
{ label: 'Content owners', fields: ['CISO (security), DPO (privacy), Legal (Code of Ethics / compliance), CTO (secure coding / AI).'] },
|
||
{ label: 'Line managers', fields: ['Verify completion by deadlines and report delays to HR.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '3. Mandatory modules (core)',
|
||
content: [
|
||
{ label: 'M1 — Code of Ethics and conduct', fields: ['Duration: 1.5 h. Contents: values, conflicts of interest, reporting, sanctions. Output: signed adhesion declaration.'] },
|
||
{ label: 'M2 — Information security', fields: ['Duration: 2 h. Contents: phishing, password/MFA, data classification, device handling, incident reporting. Output: quiz ≥ 80%.'] },
|
||
{ label: 'M3 — Privacy PDPA and GDPR', fields: ['Duration: 2 h. Contents: legal bases, data subject rights, transfers, 72h breach notification, controller/processor roles. Output: quiz ≥ 80%.'] },
|
||
{ label: 'M4 — Sensitive data and product perimeters', fields: ['Duration: 1.5 h. Contents: LexAura (professional secrecy), MediAura (health data), minimization, privileged access. Output: signed understanding checklist.'] },
|
||
{ label: 'M5 — Responsible AI/ML use', fields: ['Duration: 1.5 h. Contents: bias, human oversight, model limits, prohibition of incompatible uses. Output: quiz ≥ 80%.'] },
|
||
{ label: 'M6 — Secure coding and release (technical roles)', fields: ['Duration: 2 h. Contents: OWASP top risks, secret management, pre-release checklist, SBOM. Mandatory for developers, DevOps, QA. Output: quiz ≥ 80% + checklist exercise.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '4. 90-day onboarding calendar',
|
||
content: [
|
||
{ label: 'Day 0–7 (week 1)', fields: ['M1 Code of Ethics + signed adhesion and NDA if applicable. System access only after MFA and basic security briefing (M2 excerpt).'] },
|
||
{ label: 'Day 8–30 (month 1)', fields: ['Full M2 Security + M3 Privacy. No production data access without completed M2/M3.'] },
|
||
{ label: 'Day 31–60 (month 2)', fields: ['M4 Product perimeters (LexAura/MediAura by role) + M5 AI. Technical roles: start M6.'] },
|
||
{ label: 'Day 61–90 (month 3)', fields: ['Complete M6 (if required). Manager review: gaps, extra training, register confirmation. HR checkpoint: 100% role-mandatory modules.'] },
|
||
],
|
||
note: 'Hard deadlines: adhesion within 7 days; core M2–M5 within 60 days; M6 within 90 days for technical roles. Delays > 14 days: escalate to HR and manager; access may be limited.',
|
||
},
|
||
{
|
||
title: '5. Annual recurring training',
|
||
content: [
|
||
'Mandatory refresh within 12 months of previous completion (or onboarding date).',
|
||
'Minimum aggregate duration: 3 hours (updated M1 + M2/M3 regulatory deltas + AI reminder).',
|
||
'Additional triggers: material regulatory change, major incident, new product perimeter, critical role change.',
|
||
'Allowed formats: live session, async e-learning with quiz, or documented internal workshop.',
|
||
],
|
||
},
|
||
{
|
||
title: '6. Extra training for critical roles',
|
||
content: [
|
||
{ label: 'CISO / security', fields: ['Incident response playbook, annual tabletop, threat modeling.'] },
|
||
{ label: 'DPO / privacy', fields: ['DPIA workshop, data subject rights, international transfers.'] },
|
||
{ label: 'Legal & compliance', fields: ['LexAura/MediAura regulatory updates, sub-processor contracts.'] },
|
||
{ label: 'Engineering / DevOps', fields: ['Advanced secure SDLC, SBOM review, penetration test findings walkthrough.'] },
|
||
{ label: 'Support / customer success', fields: ['Least privilege on customer data, escalation scripts, no use outside tickets.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Delivery and materials',
|
||
content: [
|
||
'Languages: Italian, English, Thai (aligned with the site and Code of Ethics).',
|
||
'Materials: internal slides/videos, current Code of Ethics, operational annexes (checklist, DPIA, AI impact).',
|
||
'Assessment: multiple-choice quiz (80% threshold) or attendance attestation + exercise for workshops.',
|
||
'Retake: if quiz fails, retry within 14 days with domain-owner tutoring.',
|
||
],
|
||
},
|
||
{
|
||
title: '8. Training register (row template)',
|
||
content: [
|
||
{
|
||
label: 'Mandatory fields per record',
|
||
fields: [
|
||
'Collaborator name',
|
||
'Role',
|
||
'Module (M1–M6 / annual / critical)',
|
||
'Date',
|
||
'Duration (h)',
|
||
'Result (passed / retake)',
|
||
'Evidence (quiz link / PDF / signature)',
|
||
'Verification owner',
|
||
],
|
||
},
|
||
],
|
||
note: 'Register retention: aligned with the retention policy (training records and adhesion declarations). Recommended format: shared sheet or HRIS with audit export.',
|
||
},
|
||
{
|
||
title: '9. KPIs and control',
|
||
content: [
|
||
'% onboarding with mandatory modules completed within 90 days (target ≥ 95%).',
|
||
'% staff with annual refresh in good standing (target ≥ 95%).',
|
||
'Average completion time for M1–M5.',
|
||
'Number of delays > 14 days and corrective actions.',
|
||
],
|
||
},
|
||
],
|
||
footer: 'Plan approval: HR _______ · CISO _______ · DPO _______ · Date _______',
|
||
},
|
||
{
|
||
id: 'security-disclosure',
|
||
heading: 'Responsible disclosure and vulnerability reporting policy',
|
||
description: 'How to report security vulnerabilities to NexStudio: channel, response times, scope and good-faith rules (soft bug bounty).',
|
||
intro:
|
||
'Operational document linked to section 11 of the Code of Ethics (vulnerability management). Official channel: security@nexstudio.com. A paid bug bounty program may be added later without changing this channel.',
|
||
sections: [
|
||
{
|
||
title: '1. Purpose',
|
||
content: [
|
||
'Allow researchers and users to report vulnerabilities in good faith, with defined response times and without legal risk if they follow this policy.',
|
||
'Protect customer, patient and firm data (LexAura / MediAura) and SaaS availability.',
|
||
],
|
||
},
|
||
{
|
||
title: '2. Scope (in scope)',
|
||
content: [
|
||
'Public NexStudio websites and web apps (main domain and IT/EN/TH subpages).',
|
||
'Authenticated APIs and endpoints of LexAura and MediAura exposed in production or public staging.',
|
||
'Cloud infrastructure directly attributable to NexStudio and reachable from the Internet.',
|
||
'Misconfigurations exposing personal data, secrets, backups or admin panels.',
|
||
],
|
||
},
|
||
{
|
||
title: '3. Out of scope',
|
||
content: [
|
||
'DoS/DDoS, flooding, uncoordinated stress tests.',
|
||
'Social engineering of employees, customers or vendors (phishing, pretexting).',
|
||
'Spam, malware delivery, physical security.',
|
||
'Vulnerabilities in third-party products not operated by NexStudio, unless caused by our misconfiguration.',
|
||
'Scanner-only reports without a reproducible PoC.',
|
||
'Findings already known and in remediation.',
|
||
],
|
||
},
|
||
{
|
||
title: '4. Good-faith testing rules',
|
||
content: [
|
||
'Do not access, modify or delete third-party data beyond what is strictly needed to demonstrate the issue.',
|
||
'Stop immediately if real personal or health data is encountered; report without exfiltrating.',
|
||
'Do not run exploits that degrade service or compromise other users.',
|
||
'Do not demand ransom or disclose publicly before coordination (reasonable embargo).',
|
||
'Use your own test accounts or staging environments when available.',
|
||
],
|
||
},
|
||
{
|
||
title: '5. How to report',
|
||
content: [
|
||
{ label: 'Channel', fields: ['Email: security@nexstudio.com (optional PGP later, if published).'] },
|
||
{
|
||
label: 'Minimum report contents',
|
||
fields: [
|
||
'Short title',
|
||
'URL / endpoint / component',
|
||
'Description and impact',
|
||
'Reproduction steps (PoC)',
|
||
'Estimated severity (Low/Medium/High/Critical)',
|
||
'Follow-up contact',
|
||
'If data was seen: categories and volume (do not attach the data itself)',
|
||
],
|
||
},
|
||
],
|
||
note: 'Suggested subject: [SECURITY] short title. Do not attach dumps of real data.',
|
||
},
|
||
{
|
||
title: '6. Response and remediation SLAs',
|
||
content: [
|
||
{ label: 'Ack (receipt)', fields: ['Within 72 business hours of a valid report.'] },
|
||
{ label: 'Initial triage', fields: ['Within 5 business days: in/out of scope and preliminary severity.'] },
|
||
{
|
||
label: 'Indicative fix targets',
|
||
fields: [
|
||
'Critical: immediate containment; fix or mitigation within 7 days',
|
||
'High: 14 days',
|
||
'Medium: 30 days',
|
||
'Low: 90 days or next release cycle',
|
||
],
|
||
},
|
||
{ label: 'Communication', fields: ['Updates to the reporter until closure; optional public advisory after fix, with credit if requested.'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Safe harbor',
|
||
content: [
|
||
'NexStudio will not pursue legal action against good-faith reporters who follow this policy and applicable law.',
|
||
'Safe harbor does not cover out-of-scope activity, data theft, extortion or intentional harm.',
|
||
],
|
||
},
|
||
{
|
||
title: '8. Recognition and bug bounty',
|
||
content: [
|
||
'Current phase (soft bounty): written thanks and, if the reporter agrees, mention in a hall of fame / advisory.',
|
||
'Cash or swag rewards: not guaranteed; may be introduced later with a public grid without changing the security@ channel.',
|
||
'Duplicates and out-of-scope: polite ack without reward.',
|
||
],
|
||
},
|
||
{
|
||
title: '9. Internal owners',
|
||
content: [
|
||
{ label: 'CISO / Security', fields: ['Triage, remediation, reporter communication.'] },
|
||
{ label: 'DPO', fields: ['Involved if the issue implies personal data or a breach.'] },
|
||
{ label: 'Legal', fields: ['Safe harbor assessment and public disclosure.'] },
|
||
{ label: 'CTO', fields: ['Technical priority and fix resources.'] },
|
||
],
|
||
},
|
||
],
|
||
footer: 'Policy approval: CISO _______ · CTO _______ · Legal _______ · Date _______',
|
||
},
|
||
],
|
||
},
|
||
th: {
|
||
page: {
|
||
title: 'ภาคผนวกประมวลจริยธรรม — NexStudio',
|
||
description: 'เทมเพลตปฏิบัติการแนบท้ายประมวลจริยธรรม NexStudio: การยอมรับ, NDA, เช็กลิสต์, DPIA, ความเป็นส่วนตัว, SBOM, การเก็บรักษา, AI impact, แผนการฝึกอบรม, responsible disclosure',
|
||
heading: 'ภาคผนวกและแบบฟอร์มปฏิบัติการ',
|
||
lead: 'เอกสารเสริมประมวลจริยธรรม แต่ละภาคผนวกเป็นเทมเพลตที่ต้องปรับแต่งและนำไปใช้ตามความต้องการเชิงปฏิบัติการ',
|
||
backLabel: '← กลับไปประมวลจริยธรรม',
|
||
},
|
||
allegati: [
|
||
{
|
||
id: 'adesione',
|
||
heading: 'ประกาศยอมรับประมวลจริยธรรมส่วนบุคคล',
|
||
description: 'แบบฟอร์มให้ลงนามโดยผู้ร่วมงานทุกคนในขั้นตอนการปฐมนิเทศ',
|
||
intro: 'ให้กรอก ลงนาม และเก็บในแฟ้มบุคลากร',
|
||
sections: [
|
||
{
|
||
content: [
|
||
{ label: 'ชื่อ-นามสกุล', fields: ['_____________________________'] },
|
||
{ label: 'บทบาท / ตำแหน่ง', fields: ['_____________________________'] },
|
||
{ label: 'วันที่ปฐมนิเทศ', fields: ['_____________________________'] },
|
||
{ label: 'ลายเซ็น', fields: ['_____________________________'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'คำประกาศ',
|
||
intro: 'ข้าพเจ้าขอประกาศว่า:',
|
||
content: [
|
||
'ได้รับ อ่าน และเข้าใจประมวลจริยธรรมของ NexStudio ฉบับปัจจุบันแล้ว',
|
||
'สัญญาว่าจะเคารพหลักการ กฎการประพฤติ และขั้นตอนที่กำหนดไว้',
|
||
'ได้รับหรือจะได้รับตามแผนการฝึกอบรม ซึ่งการฝึกอบรมบังคับเกี่ยวกับความปลอดภัยสารสนเทศ ความเป็นส่วนตัว (PDPA และ GDPR) การจัดการข้อมูลอ่อนไหว การใช้ AI อย่างรับผิดชอบ และแนวปฏิบัติการเขียนโค้ดอย่างปลอดภัย',
|
||
'สัญญาว่าจะรายงานโดยสุจริตผ่านช่องทางที่กำหนด การละเมิดประมวลใดๆ ที่ข้าพเจ้าทราบ',
|
||
'ทราบว่าการละเมิดประมวลอาจนำไปสู่มาตรการทางวินัยตามสัดส่วน รวมถึงการสิ้นสุดความสัมพันธ์ตามสัญญา',
|
||
'ยอมรับให้คำประกาศนี้เก็บในแฟ้มบุคลากรและใช้เพื่อการกำกับดูแลองค์กร',
|
||
],
|
||
},
|
||
],
|
||
footer: 'สถานที่และวันที่: _____________________ · ลายเซ็น: _____________________',
|
||
},
|
||
{
|
||
id: 'nda',
|
||
heading: 'เทมเพลต NDA และข้อสัญญาน้อยสุดสำหรับผู้ให้บริการและผู้ประมวลผลช่วง',
|
||
description: 'ข้อตกลงการรักษาความลับมาตรฐานสำหรับผู้ร่วมงานภายนอก ที่ปรึกษา ผู้ให้บริการ และผู้ประมวลผลช่วง',
|
||
sections: [
|
||
{
|
||
title: '1. คำนิยามข้อมูลที่เป็นความลับ',
|
||
content: [
|
||
'"ข้อมูลที่เป็นความลับ" หมายถึง ข้อมูล เอกสาร ความรู้ รหัสต้นฉบับ ข้อกำหนดทางเทคนิค กลยุทธ์ทางการค้า ข้อมูลส่วนบุคคลหรือข้อมูลอ่อนไหว การสื่อสารหรือวัสดุใดๆ — ในรูปแบบใดก็ตาม (ลายลักษณ์อักษร วาจา อิเล็กทรอนิกส์ ภาพ) — ที่ฝ่ายหนึ่ง ("ฝ่ายเปิดเผย") สื่อสารกับอีกฝ่าย ("ฝ่ายรับ") ที่เกี่ยวข้องกับวัตถุประสงค์ของความสัมพันธ์ โดยไม่คำนึงว่าจะระบุว่าเป็นความลับอย่างชัดแจ้งหรือไม่',
|
||
'ข้อมูลที่เป็นความลับยังรวมถึงข้อมูลส่วนบุคคลที่ประมวลผลในนามของผู้ควบคุม ข้อมูลเกี่ยวกับผู้ป่วย ลูกค้า และผู้รับการดูแล (สำหรับขอบเขต Legal Tech และ Health Tech) บันทึกระบบ ข้อมูลประจำตัว และผลการทดสอบและการตรวจสอบ',
|
||
],
|
||
},
|
||
{
|
||
title: '2. หน้าที่ของฝ่ายรับ',
|
||
content: [
|
||
'ใช้ข้อมูลที่เป็นความลับเฉพาะเพื่อวัตถุประสงค์ที่ตกลงกันและเพื่อการปฏิบัติตามความสัมพันธ์ตามสัญญาเท่านั้น',
|
||
'ไม่เปิดเผย คัดลอก ทำซ้ำ หรือแจกจ่ายข้อมูลที่เป็นความลับแก่บุคคลภายนอกโดยไม่ได้รับอนุญาตเป็นลายลักษณ์อักษรล่วงหน้าจากฝ่ายเปิดเผย',
|
||
'จำกัดการเข้าถึงข้อมูลที่เป็นความลับเฉพาะบุคคลที่ได้รับอนุญาตที่มีความจำเป็นต้องรู้และผูกพันตามหน้าที่การรักษาความลับอย่างน้อยเทียบเท่า',
|
||
'ใช้มาตรการความปลอดภัยทางเทคนิคและองค์กรที่เพียงพอเพื่อป้องกันข้อมูลที่เป็นความลับจากการเข้าถึงโดยไม่ได้รับอนุญาต การสูญหาย การโจรกรรม หรือการเปิดเผย',
|
||
'ในกรณีการมอบช่วง (sub-processing) ขออนุญาตเป็นลายลักษณ์อักษรล่วงหน้าและกำหนดหน้าที่ตามสัญญาเทียบเท่าแก่ผู้ประมวลผลช่วง',
|
||
],
|
||
},
|
||
{
|
||
title: '3. ข้อยกเว้น',
|
||
content: [
|
||
'ข้อมูลที่เป็นสาธารณสมบัติอยู่แล้วโดยไม่ละเมิดข้อตกลงนี้',
|
||
'ข้อมูลที่ฝ่ายรับครอบครองอยู่แล้วก่อนการเปิดเผย ตามที่บันทึกไว้',
|
||
'ข้อมูลที่ได้รับโดยชอบจากบุคคลภายนอกโดยไม่มีหน้าที่รักษาความลับ',
|
||
'ข้อมูลที่ฝ่ายรับต้องเปิดเผยตามกฎหมายหรือคำสั่งเจ้าหน้าที่ (โดยแจ้งฝ่ายเปิดเผยล่วงหน้าเมื่อทำได้)',
|
||
],
|
||
},
|
||
{
|
||
title: '4. การแจ้งเมื่อเกิดการละเมิด (Breach Notification)',
|
||
content: [
|
||
'ฝ่ายรับต้องแจ้งฝ่ายเปิดเผยถึงการเข้าถึงโดยไม่ได้รับอนุญาต การสูญหาย หรือการเปิดเผยข้อมูลที่เป็นความลับ ภายใน 24 ชั่วโมงนับแต่พบ โดยระบุ: คำอธิบายเหตุการณ์ ข้อมูลและหมวดหมู่ข้อมูลที่เกี่ยวข้อง มาตรการที่ดำเนินการหรือเสนอเพื่อบรรเทาผลกระทบ จุดติดต่อสำหรับข้อมูล',
|
||
],
|
||
},
|
||
{
|
||
title: '5. ระยะเวลาและการคืน',
|
||
content: [
|
||
'หน้าที่รักษาความลับมีผลตลอดระยะเวลาความสัมพันธ์และ 5 ปีหลังจากสิ้นสุด เว้นแต่มีหน้าที่ตามกฎหมายที่ยาวกว่า',
|
||
'เมื่อสิ้นสุดความสัมพันธ์ ฝ่ายรับต้องคืนหรือทำลายข้อมูลที่เป็นความลับทั้งหมด โดยให้หนังสือรับรอง',
|
||
],
|
||
},
|
||
{
|
||
title: '6. มาตรการความปลอดภัยเทียบเท่า',
|
||
content: [
|
||
'การเข้ารหัสขณะพักและขณะส่งด้วยอัลกอริทึมที่ทันสมัย (ขั้นต่ำ AES-256, TLS 1.3)',
|
||
'การควบคุมการเข้าถึงด้วยหลักสิทธิ์น้อยที่สุดและ MFA บังคับ',
|
||
'บันทึกที่แก้ไขไม่ได้สำหรับการเข้าถึงข้อมูลอ่อนไหว',
|
||
'ขั้นตอนจัดการเหตุการณ์ที่บันทึกไว้',
|
||
'การฝึกอบรมพนักงานเกี่ยวกับความปลอดภัยและความเป็นส่วนตัว',
|
||
],
|
||
},
|
||
{
|
||
title: '7. กฎหมายที่ใช้บังคับและเขตอำนาจศาล',
|
||
content: [
|
||
'กฎหมายไทย โดยอาจอ้างถึงข้อ GDPR/PDPA สำหรับการประมวลผลข้อมูลส่วนบุคคล ศาลที่มีเขตอำนาจ: กรุงเทพฯ ประเทศไทย เว้นแต่ตกลงเป็นลายลักษณ์อักษรเป็นอย่างอื่น',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'checklist-prerelease',
|
||
heading: 'เช็กลิสต์ก่อนปล่อย — ความปลอดภัยและความเป็นส่วนตัว',
|
||
description: 'รายการตรวจสอบบังคับก่อนการปล่อยสู่ production ทุกครั้ง',
|
||
sections: [
|
||
{
|
||
title: 'ความปลอดภัย',
|
||
content: [
|
||
{ label: 'Code review เสร็จสิ้นและอนุมัติแล้ว', fields: ['[ ]'] },
|
||
{ label: 'การทดสอบอัตโนมัติผ่าน (CI สีเขียว)', fields: ['[ ]'] },
|
||
{ label: 'การวิเคราะห์โค้ดแบบคงที่ (SAST) ไม่มีช่องโหว่ระดับวิกฤตหรือสูง', fields: ['[ ]'] },
|
||
{ label: 'การสแกนการพึ่งพา (SCA) ไม่มีช่องโหว่ที่ทราบด้วย CVSS ≥ 7', fields: ['[ ]'] },
|
||
{ label: 'Penetration test หรือสแกนแบบพลวัต (DAST) ทำบน build ก่อนปล่อย', fields: ['[ ]'] },
|
||
{ label: 'ไม่มีข้อมูลประจำตัว โทเค็น หรือความลับที่ฝังในโค้ด', fields: ['[ ]'] },
|
||
{ label: 'HTTP security headers ตั้งค่าแล้ว (HSTS, CSP, X-Frame-Options, ฯลฯ)', fields: ['[ ]'] },
|
||
{ label: 'CORS ตั้งค่าถูกต้อง (ไม่มี wildcard บน origin ที่อ่อนไหว)', fields: ['[ ]'] },
|
||
{ label: 'Rate limiting ทำงานบน endpoint สาธารณะ', fields: ['[ ]'] },
|
||
{ label: 'การพึ่งพาอัปเดตเป็นเวอร์ชันเสถียรล่าสุด (หรือแพตช์ความปลอดภัยใช้แล้ว)', fields: ['[ ]'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'ความเป็นส่วนตัวและข้อมูล',
|
||
content: [
|
||
{ label: 'ไม่มีข้อมูลส่วนบุคคลจริงในสภาพแวดล้อมทดสอบ (เฉพาะข้อมูลสังเคราะห์/ไม่ระบุตัวตน)', fields: ['[ ]'] },
|
||
{ label: 'การเข้ารหัสขณะพักเปิดใช้สำหรับข้อมูลอ่อนไหวทั้งหมด', fields: ['[ ]'] },
|
||
{ label: 'การเข้ารหัสขณะส่ง (TLS 1.3) ทำงานบนทุก endpoint', fields: ['[ ]'] },
|
||
{ label: 'บันทึกไม่มีข้อมูลส่วนบุคคลหรือข้อมูลอ่อนไหวในรูปแบบข้อความธรรมดา', fields: ['[ ]'] },
|
||
{ label: 'กลไกความยินยอมตรวจสอบได้และบันทึกไว้ (ถ้ามี)', fields: ['[ ]'] },
|
||
{ label: 'ขั้นตอนการลบ/สิทธิในการลบ ทดสอบแล้วและทำงาน', fields: ['[ ]'] },
|
||
{ label: 'นโยบายการเก็บรักษานำไปใช้และตรวจสอบแล้ว', fields: ['[ ]'] },
|
||
{ label: 'DPIA อัปเดตสำหรับการประมวลผลที่เกี่ยวข้องในการปล่อยนี้', fields: ['[ ]'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'ปฏิบัติการ',
|
||
content: [
|
||
{ label: 'แผน rollback บันทึกและทดสอบแล้ว', fields: ['[ ]'] },
|
||
{ label: 'Changelog จัดทำพร้อมผลกระทบที่ทราบ', fields: ['[ ]'] },
|
||
{ label: 'แจ้งผู้มีส่วนได้ส่วนเสียภายใน (สนับสนุน ความปลอดภัย DPO)', fields: ['[ ]'] },
|
||
{ label: 'การติดตามและ alerting ตั้งค่าสำหรับฟีเจอร์ใหม่', fields: ['[ ]'] },
|
||
],
|
||
note: 'ลายเซ็น: ผู้พัฒนา _______ ผู้ตรวจสอบ _______ CISO/DPO _______ วันที่ _______',
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'incident-management',
|
||
heading: 'การจัดการเหตุการณ์ — แผนภูมิและเทมเพลตการแจ้ง',
|
||
description: 'ขั้นตอนปฏิบัติและแบบการสื่อสารสำหรับจัดการเหตุการณ์ความปลอดภัยและการละเมิดข้อมูล',
|
||
sections: [
|
||
{
|
||
title: 'แผนภูมิ: ขั้นตอนการจัดการเหตุการณ์',
|
||
content: [
|
||
'1. การตรวจจับ — เหตุการณ์ถูกตรวจพบโดย: ระบบติดตามอัตโนมัติ, การรายงานภายใน, bug bounty/ผู้รายงานภายนอก, การแจ้งจากผู้ให้บริการหรือพันธมิตร',
|
||
'2. การคัดแยกและจำแนกประเภท (สูงสุด 1 ชั่วโมง) — ทีมความปลอดภัยประเมิน: ประเภทเหตุการณ์ (การละเมิดข้อมูล, การเข้าถึงโดยไม่ได้รับอนุญาต, มัลแวร์, DDoS, ฯลฯ), ความรุนแรง (ต่ำ/กลาง/สูง/วิกฤต), ขอบเขตที่เกี่ยวข้อง (แพลตฟอร์ม, Legal Tech, Health Tech), ข้อมูลที่เกี่ยวข้อง (ส่วนบุคคล, อ่อนไหว, สุขภาพ, กฎหมาย)',
|
||
'3. การกักกัน (ทันที) — แยกระบบที่ถูกบุกรุก, ยกเลิกข้อมูลประจำตัวหรือโทเค็นที่เปิดเผย, บล็อก IP หรือบัญชีที่เป็นอันตราย, เรียกทีมตอบสนองที่กำหนด',
|
||
'4. การกำจัด — ลบสาเหตุต้นตอ (แพตช์, กำหนดค่าใหม่, กำจัดมัลแวร์), ตรวจสอบว่าไม่มี backdoor หรือการคงอยู่, บันทึกการดำเนินการ',
|
||
'5. การกู้คืน — กู้คืนระบบจาก backup ที่สะอาด, ใช้แพตช์และการบรรเทา, ตรวจสอบการทำงานในสภาพแวดล้อมแยกก่อนกลับสู่ production',
|
||
'6. การแจ้ง — ภายใน 72 ชั่วโมงนับแต่พบ: แจ้ง DPO และ Legal & Compliance; หากเป็นการละเมิดข้อมูลส่วนบุคคล ประเมินหน้าที่แจ้งหน่วยงาน (PDPA/GDPR) และเจ้าของข้อมูล ใช้เทมเพลตการแจ้ง (ดูด้านล่าง)',
|
||
'7. POST-MORTEM (ภายใน 5 วันทำการ) — วิเคราะห์สาเหตุต้นตอ, บทเรียนที่ได้รับ, อัปเดต playbook และการควบคุมความปลอดภัย, การสื่อสารภายใน (ไม่ตำหนิ)',
|
||
],
|
||
},
|
||
{
|
||
title: 'เทมเพลตการแจ้งเหตุการณ์',
|
||
intro: 'ส่งภายใน และหากจำเป็น ภายนอก',
|
||
content: [
|
||
{ label: 'รหัสเหตุการณ์', fields: ['INC-YYYY-NNN'] },
|
||
{ label: 'วันที่และเวลาที่ตรวจพบ', fields: ['_____________________'] },
|
||
{ label: 'วันที่และเวลาที่กักกัน', fields: ['_____________________'] },
|
||
{ label: 'ความรุนแรง', fields: ['[ ] ต่ำ [ ] กลาง [ ] สูง [ ] วิกฤต'] },
|
||
{ label: 'ประเภท', fields: ['[ ] การละเมิดข้อมูล [ ] การเข้าถึงโดยไม่ได้รับอนุญาต [ ] มัลแวร์ [ ] DDoS [ ] อื่นๆ: ___'] },
|
||
{ label: 'ขอบเขต', fields: ['[ ] แพลตฟอร์ม [ ] Legal Tech / LexAura [ ] Health Tech / MediAura'] },
|
||
{ label: 'ระบบที่เกี่ยวข้อง', fields: ['_____________________'] },
|
||
{ label: 'ข้อมูลที่เกี่ยวข้อง', fields: ['หมวดหมู่: ___ จำนวนเจ้าของข้อมูลโดยประมาณ: ___'] },
|
||
{ label: 'คำอธิบาย', fields: ['_____________________'] },
|
||
{ label: 'การดำเนินการ', fields: ['_____________________'] },
|
||
{ label: 'มาตรการสำหรับเจ้าของข้อมูล', fields: ['_____________________'] },
|
||
{ label: 'จุดติดต่อ', fields: ['ชื่อ: ___ อีเมล: ___ โทรศัพท์: ___'] },
|
||
{ label: 'ผู้จัดทำ', fields: ['_____________________'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'dpia',
|
||
heading: 'แบบ DPIA แบบย่อและตัวอย่างที่กรอกแล้ว',
|
||
description: 'Data Protection Impact Assessment — แบบพื้นฐานตาม PDPA และ GDPR',
|
||
sections: [
|
||
{
|
||
title: 'แบบ DPIA — ส่วนที่จำเป็น',
|
||
content: [
|
||
{ label: '1. ชื่อการประมวลผล', fields: ['คำอธิบายย่อของการประมวลผลที่ประเมิน'] },
|
||
{ label: '2. ผู้ควบคุมและผู้ประมวลผล', fields: ['ผู้ควบคุม: ___ ผู้ประมวลผล: ___ ผู้ประมวลผลช่วง: ___ DPO: ___'] },
|
||
{ label: '3. วัตถุประสงค์การประมวลผล', fields: ['อธิบายว่าทำไมข้อมูลถูกประมวลผล ฐานทางกฎหมาย และความจำเป็น'] },
|
||
{ label: '4. หมวดหมู่ข้อมูล', fields: ['[ ] ส่วนบุคคลทั่วไป [ ] หมวดหมู่พิเศษ (สุขภาพ กฎหมาย ชีวมิติ) [ ] อาญา'] },
|
||
{ label: '5. หมวดหมู่เจ้าของข้อมูล', fields: ['[ ] ผู้ป่วย [ ] ลูกค้าสำนักงาน [ ] พนักงาน [ ] ผู้ใช้แพลตฟอร์ม [ ] อื่นๆ: ___'] },
|
||
{ label: '6. การดำเนินการประมวลผล', fields: ['การเก็บรวบรวม การบันทึก การจัดระเบียบ การจัดเก็บ การปรึกษา การเปิดเผย การลบ ฯลฯ'] },
|
||
{ label: '7. เทคโนโลยีที่ใช้', fields: ['ฐานข้อมูล คลาวด์ API AI/ML ฯลฯ'] },
|
||
{ label: '8. การประเมินความเสี่ยง', fields: ['ความน่าจะเป็น × ผลกระทบ สำหรับแต่ละความเสี่ยงที่ระบุ มาตรการบรรเทาที่วางแผนไว้'] },
|
||
{ label: '9. มาตรการความปลอดภัย', fields: ['การเข้ารหัส การควบคุมการเข้าถึง การบันทึก การสำรองข้อมูล ฯลฯ'] },
|
||
{ label: '10. การปรึกษา DPO', fields: ['ความเห็น DPO: ___ วันที่: ___'] },
|
||
{ label: '11. การตัดสินใจสุดท้าย', fields: ['[ ] ความเสี่ยงยอมรับได้ [ ] ความเสี่ยงบรรเทาแล้ว [ ] ต้องปรึกษาหน่วยงาน [ ] ไม่ควรเริ่มการประมวลผล'] },
|
||
{ label: '12. วันที่และลายเซ็น', fields: ['ผู้จัดทำ: ___ DPO: ___ ผู้ควบคุม: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'ตัวอย่างที่กรอกแล้ว — MediAura: การจัดการข้อมูลคลินิกบนคลาวด์',
|
||
content: [
|
||
{ label: '1. ชื่อ', fields: ['การจัดการและจัดเก็บข้อมูลคลินิกผู้ป่วยบนแพลตฟอร์ม MediAura (คลาวด์ กรุงเทพฯ)'] },
|
||
{ label: '2. ผู้ควบคุมและผู้ประมวลผล', fields: ['ผู้ควบคุม: คลินิก/สถานพยาบาลที่สมัครสมาชิก ผู้ประมวลผล: NexStudio ผู้ประมวลผลช่วง: ผู้ให้บริการคลาวด์รับรอง ISO 27001'] },
|
||
{ label: '3. วัตถุประสงค์', fields: ['จัดเก็บและปรึกษาข้อมูลคลินิกเพื่อสนับสนุนการประกอบวิชาชีพเวชกรรม ฐานทางกฎหมาย: การปฏิบัติตามสัญญาและความยินยอมผู้ป่วย (ประกาศลงนามแล้ว)'] },
|
||
{ label: '4. หมวดหมู่ข้อมูล', fields: ['หมวดหมู่พิเศษ: ข้อมูลสุขภาพ (การวินิจฉัย ใบสั่งยา รายงาน) ส่วนบุคคลทั่วไป: ข้อมูลประจำตัว การติดต่อ'] },
|
||
{ label: '5. เจ้าของข้อมูล', fields: ['ผู้ป่วย (ผู้ใหญ่และผู้เยาว์ผ่านผู้ปกครอง)'] },
|
||
{ label: '6. การดำเนินการ', fields: ['การเก็บรวบรวม การบันทึก การจัดระเบียบ การจัดเก็บ การปรึกษาโดยเจ้าหน้าที่ที่ได้รับอนุญาต การลบตามคำขอ'] },
|
||
{ label: '7. เทคโนโลยี', fields: ['ฐานข้อมูลเข้ารหัส (AES-256) REST API พร้อม TLS 1.3 AI สำหรับข้อเสนอแนะทางคลินิก (ต้องมีมนุษย์กำกับ)'] },
|
||
{ label: '8. ความเสี่ยง', fields: ['การเข้าถึงข้อมูลสุขภาพโดยไม่ได้รับอนุญาต (ความน่าจะเป็นต่ำ ผลกระทบสูง → บรรเทาด้วย MFA การเข้ารหัส และ audit log) การสูญหายข้อมูล (ความน่าจะเป็นต่ำ ผลกระทบวิกฤต → บรรเทาด้วย backup รายวัน disaster recovery ที่ทดสอบแล้ว)'] },
|
||
{ label: '9. มาตรการความปลอดภัย', fields: ['การเข้ารหัสขณะพัก AES-256 และขณะส่ง TLS 1.3 MFA บังคับ บันทึกที่แก้ไขไม่ได้ backup อัตโนมัติรายวัน ทดสอบกู้คืนรายไตรมาส'] },
|
||
{ label: '10. DPO', fields: ['ความเห็นชอบ พร้อมคำแนะนำให้ตรวจสอบประจำปี'] },
|
||
{ label: '11. การตัดสินใจ', fields: ['ความเสี่ยงบรรเทาแล้ว — อนุมัติการประมวลผลพร้อมทบทวนประจำปี'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'privacy-notice',
|
||
heading: 'แบบประกาศความเป็นส่วนตัวและแบบความยินยอม',
|
||
description: 'เทมเพลตประกาศความเป็นส่วนตัวตาม PDPA และ GDPR พร้อมแบบความยินยอมในตัว',
|
||
sections: [
|
||
{
|
||
title: 'ประกาศการประมวลผลข้อมูลส่วนบุคคล',
|
||
intro: 'ตาม PDPA (ประเทศไทย) และ GDPR (EU) เมื่อใช้บังคับ',
|
||
content: [
|
||
{ label: 'ผู้ควบคุมข้อมูล', fields: ['[ชื่อสำนักงาน/องค์กร] ที่อยู่ [ที่อยู่] อีเมล: [___] โทรศัพท์: [___]'] },
|
||
{ label: 'ผู้ประมวลผลข้อมูล (ผู้ให้บริการแพลตฟอร์ม)', fields: ['NexStudio กรุงเทพฯ ประเทศไทย อีเมล: privacy@nexstudio.com'] },
|
||
{ label: 'วัตถุประสงค์การประมวลผล', fields: ['การจัดการบริการ [กฎหมาย/สุขภาพ] การจัดเก็บเอกสาร การสื่อสารเกี่ยวกับบริการ หน้าที่ตามกฎหมาย'] },
|
||
{ label: 'ฐานทางกฎหมาย', fields: ['[ความยินยอมเจ้าของข้อมูล / การปฏิบัติตามสัญญา / หน้าที่ตามกฎหมาย / ประโยชน์อันชอบธรรม]'] },
|
||
{ label: 'หมวดหมู่ข้อมูล', fields: ['ข้อมูลประจำตัวและการติดต่อ ข้อมูลเกี่ยวกับการปฏิบัติ [กฎหมาย/สุขภาพ] [หากสุขภาพ: ข้อมูลสุขภาพตามมาตรา 9 GDPR / PDPA]'] },
|
||
{ label: 'ระยะเวลาเก็บรักษา', fields: ['[X ปี] จากสิ้นสุดความสัมพันธ์ หรือตามนโยบายการเก็บรักษา'] },
|
||
{ label: 'ผู้รับข้อมูล', fields: ['เจ้าหน้าที่ผู้ควบคุมที่ได้รับอนุญาต NexStudio (ผู้ประมวลผลข้อมูล) ผู้ให้บริการคลาวด์ (ผู้ประมวลผลช่วงพร้อมหลักประกันตามสัญญา) หน่วยงานของรัฐ หากกฎหมายกำหนด'] },
|
||
{ label: 'การโอนระหว่างประเทศ', fields: ['[อธิบายว่าข้อมูลถูกโอนนอกประเทศไทย/EU หรือไม่ และบนฐานทางกฎหมายใด]'] },
|
||
{ label: 'สิทธิเจ้าของข้อมูล', fields: ['การเข้าถึง การแก้ไข การลบ การจำกัด การโอนย้าย การคัดค้าน การถอนความยินยอม เพื่อใช้สิทธิ ติดต่อผู้ควบคุมตามที่อยู่ข้างต้น'] },
|
||
{ label: 'ข้อร้องเรียน', fields: ['เจ้าของข้อมูลมีสิทธิร้องเรียนต่อหน่วยงานควบคุมที่เกี่ยวข้อง (PDPC ในประเทศไทย / หน่วยงานคุ้มครองข้อมูลใน EU)'] },
|
||
],
|
||
},
|
||
{
|
||
title: 'แบบความยินยอม',
|
||
intro: 'ให้เจ้าของข้อมูลกรอกและลงนาม',
|
||
content: [
|
||
'ข้าพเจ้า _____________________ เกิดวันที่ ____________',
|
||
'ขอประกาศว่าได้รับและอ่านประกาศการประมวลผลข้อมูลส่วนบุคคลแล้ว',
|
||
'',
|
||
'[ ] ยินยอมให้ประมวลผลข้อมูลส่วนบุคคลเพื่อวัตถุประสงค์ที่ระบุในประกาศ',
|
||
'[ ] ยินยอมให้ประมวลผลข้อมูลหมวดหมู่พิเศษ (เช่น ข้อมูลสุขภาพ / ข้อมูลกฎหมาย) เพื่อวัตถุประสงค์ที่ระบุ',
|
||
'[ ] ยินยอมให้เปิดเผยข้อมูลแก่บุคคลที่ระบุในประกาศ',
|
||
'',
|
||
'วันที่: ____________ ลายเซ็น: _____________________',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'sbom',
|
||
heading: 'เทมเพลต SBOM — Software Bill of Materials',
|
||
description: 'รายการส่วนประกอบซอฟต์แวร์ ใบอนุญาต และช่องโหว่ ในรูปแบบที่อ่านได้',
|
||
sections: [
|
||
{
|
||
title: 'คำแนะนำ',
|
||
intro: 'กรอกสำหรับแต่ละส่วนประกอบ open source หรือบุคคลที่สามที่ใช้ในผลิตภัณฑ์ อัปเดตทุกครั้งที่ปล่อย',
|
||
content: [
|
||
'สร้างอัตโนมัติด้วยเครื่องมือเช่น: CycloneDX, SPDX, Syft, Trivy, OWASP Dependency-Track',
|
||
'รูปแบบที่แนะนำคือ CycloneDX JSON หรือ SPDX tag-value',
|
||
'ด้านล่างเป็นเทมเพลตรูปแบบตารางสำหรับการตรวจสอบด้วยตนเอง',
|
||
],
|
||
},
|
||
{
|
||
title: 'รายการส่วนประกอบ',
|
||
content: [
|
||
{ label: 'ชื่อส่วนประกอบ', fields: ['เวอร์ชัน', 'ใบอนุญาต', 'ประเภทใบอนุญาต (copyleft/permissive)', 'ผู้ให้บริการ/URL', 'การใช้งานในผลิตภัณฑ์', 'ช่องโหว่ที่ทราบ (CVE)', 'คะแนน CVSS', 'วันที่อัปเดตล่าสุด'] },
|
||
],
|
||
note: 'ตัวอย่างแถวแรก: React | 18.3.1 | MIT | Permissive | https://react.dev | Frontend UI | ไม่มี | N/A | 2026-04-01',
|
||
},
|
||
{
|
||
title: 'สรุป',
|
||
content: [
|
||
{ label: 'ส่วนประกอบทั้งหมด', fields: ['___'] },
|
||
{ label: 'ส่วนประกอบที่มีใบอนุญาต copyleft', fields: ['___ (ตรวจสอบความเข้ากันได้)'] },
|
||
{ label: 'ส่วนประกอบที่มีช่องโหว่ที่ทราบ', fields: ['___ (รายละเอียดด้านบน)'] },
|
||
{ label: 'ส่วนประกอบที่ไม่มีใบอนุญาตระบุ', fields: ['___ (ต้องตรวจสอบ)'] },
|
||
{ label: 'วันที่สร้าง SBOM', fields: ['____________'] },
|
||
{ label: 'สร้างโดย', fields: ['[ชื่อ] — [บทบาท]'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'retention',
|
||
heading: 'นโยบายการเก็บรักษาข้อมูล',
|
||
description: 'กำหนดระยะเวลาเก็บรักษา เหตุผล และวิธีการลบสำหรับข้อมูลทุกหมวดหมู่ที่ประมวลผล',
|
||
sections: [
|
||
{
|
||
title: 'หลักการทั่วไป',
|
||
content: [
|
||
'ข้อมูลส่วนบุคคลถูกเก็บรักษาเฉพาะเวลาที่จำเป็นเพื่อบรรลุวัตถุประสงค์ที่เก็บรวบรวม',
|
||
'เมื่อสิ้นสุดระยะเวลาเก็บรักษา ข้อมูลจะถูกทำให้ไม่ระบุตัวตนหรือลบอย่างปลอดภัยและไม่สามารถกู้คืนได้',
|
||
'ระยะเวลาเก็บรักษาถูกบันทึก มีเหตุผล และแจ้งเจ้าของข้อมูลในประกาศความเป็นส่วนตัว',
|
||
'นโยบายนี้ต้องทบทวนอย่างน้อยปีละครั้งหรือเมื่อมีการเปลี่ยนแปลงกฎระเบียบ',
|
||
],
|
||
},
|
||
{
|
||
title: 'ตารางระยะเวลาเก็บรักษา',
|
||
content: [
|
||
{
|
||
label: 'ข้อมูลประจำตัวและการติดต่อ',
|
||
fields: ['ระยะเวลา: 10 ปีจากสิ้นสุดความสัมพันธ์ (หน้าที่ทางภาษีและกฎหมาย) เหตุผล: กฎหมายภาษีไทย การลบ: ทำให้ไม่ระบุตัวตนเมื่อครบกำหนด'],
|
||
},
|
||
{
|
||
label: 'ข้อมูลสุขภาพ (MediAura / Health Tech)',
|
||
fields: ['ระยะเวลา: ระยะเวลาความสัมพันธ์ + 10 ปี (หรือตามกฎระเบียบท้องถิ่นที่ใช้) เหตุผล: กฎระเบียบสุขภาพ การฟ้องร้อง ความต้องการทางคลินิก การลบ: ทำลายอย่างปลอดภัยพร้อมใบรับรอง'],
|
||
},
|
||
{
|
||
label: 'ข้อมูลกฎหมาย / แฟ้มคดี (LexAura / Legal Tech)',
|
||
fields: ['ระยะเวลา: ระยะเวลาความสัมพันธ์ + 10 ปี เหตุผล: หน้าที่จรรยาบรรณกฎหมาย อายุความ การฟ้องร้อง การลบ: หลังตรวจสอบกับผู้ควบคุมสำนักงาน'],
|
||
},
|
||
{
|
||
label: 'บันทึกการเข้าถึงและ audit trail',
|
||
fields: ['ระยะเวลา: 2 ปี เหตุผล: ความปลอดภัย การสอบสวน การปฏิบัติตามกฎ การลบ: หมุนเวียนอัตโนมัติ'],
|
||
},
|
||
{
|
||
label: 'ข้อมูลการเรียกเก็บเงิน',
|
||
fields: ['ระยะเวลา: 10 ปี เหตุผล: หน้าที่ทางภาษีและบัญชี การลบ: ทำให้ไม่ระบุตัวตนเมื่อครบกำหนด'],
|
||
},
|
||
{
|
||
label: 'ข้อมูลผู้สมัครที่ไม่ได้รับการว่าจ้าง',
|
||
fields: ['ระยะเวลา: 12 เดือนจากการสมัคร เหตุผล: โอกาสในอนาคตที่เป็นไปได้ (ด้วยความยินยอม) การลบ: ทำลายเมื่อครบกำหนด'],
|
||
},
|
||
{
|
||
label: 'คุกกี้และข้อมูลติดตาม',
|
||
fields: ['ระยะเวลา: ตามนโยบายคุกกี้ (สูงสุด 12 เดือน) เหตุผล: การวิเคราะห์และฟังก์ชันเว็บไซต์ การลบ: หมดอายุอัตโนมัติหรือตามคำขอ'],
|
||
},
|
||
{
|
||
label: 'Backup',
|
||
fields: ['ระยะเวลา: 30 วัน (backup ปฏิบัติการ) 12 เดือน (backup ประวัติ) เหตุผล: disaster recovery และความต่อเนื่องทางธุรกิจ การลบ: หมุนเวียนอัตโนมัติ ข้อมูลส่วนบุคคลใน backup อยู่ภายใต้ระยะเวลาเก็บรักษาเดียวกันและถูกลบจาก backup ที่ใช้งานเมื่อครบกำหนด'],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
title: 'วิธีการลบ',
|
||
content: [
|
||
'การลบตรรกะ: ข้อมูลถูกทำให้ไม่สามารถเข้าถึงได้โดยผู้ใช้ แต่เก็บในพื้นที่แยกสำหรับระยะเวลาเก็บรักษา',
|
||
'การลบกายภาพ: เมื่อสิ้นสุดระยะเวลาเก็บรักษา ข้อมูลถูกเขียนทับหรือทำลายอย่างไม่สามารถกู้คืนได้ (crypto-shredding, degaussing, การทำลายกายภาพสำหรับสื่อ)',
|
||
'การทำให้ไม่ระบุตัวตน: ข้อมูลถูกแปลงอย่างไม่สามารถกู้คืนได้เป็นรูปแบบนิรนาม ไม่สามารถระบุเจ้าของข้อมูลได้',
|
||
'สำหรับการลบแต่ละครั้ง มีการจัดทำหลักฐานเอกสาร (บันทึก ใบรับรอง)',
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'ai-impact',
|
||
heading: 'เทมเพลตการประเมินผลกระทบ AI/ML',
|
||
description: 'แบบสำหรับประเมินผลกระทบด้านจริยธรรม กฎหมาย และเทคนิคของระบบปัญญาประดิษฐ์และการเรียนรู้ของเครื่อง',
|
||
sections: [
|
||
{
|
||
title: 'ข้อมูลทั่วไป',
|
||
content: [
|
||
{ label: 'ชื่อระบบ/โมเดล', fields: ['_____________________'] },
|
||
{ label: 'เวอร์ชัน', fields: ['_____________________'] },
|
||
{ label: 'ขอบเขต', fields: ['[ ] แพลตฟอร์ม [ ] Legal Tech / LexAura [ ] Health Tech / MediAura'] },
|
||
{ label: 'ผู้รับผิดชอบทางเทคนิค', fields: ['_____________________'] },
|
||
{ label: 'วันที่ประเมิน', fields: ['_____________________'] },
|
||
],
|
||
},
|
||
{
|
||
title: '1. คำอธิบายระบบ AI',
|
||
content: [
|
||
'อธิบายวัตถุประสงค์ของระบบ ฟังก์ชัน ผู้ใช้เป้าหมาย และบริบทการใช้งาน ระบุว่าระบบตัดสินใจอัตโนมัติหรือให้คำแนะนำโดยมีมนุษย์กำกับ',
|
||
],
|
||
},
|
||
{
|
||
title: '2. ชุดข้อมูลและแหล่งที่มา',
|
||
content: [
|
||
{ label: 'แหล่งข้อมูล training', fields: ['[ ] ข้อมูลภายใน [ ] ข้อมูลสาธารณะ [ ] ข้อมูลบุคคลที่สาม [ ] ข้อมูลสังเคราะห์'] },
|
||
{ label: 'ปริมาณและลักษณะ', fields: ['จำนวน record: ___ Features: ___ ความสมดุลคลาส: ___'] },
|
||
{ label: 'คุณภาพและข้อจำกัดที่ทราบ', fields: ['อธิบาย bias ที่ทราบ ข้อมูลขาด เสียงรบกวน คุณภาพการติดป้าย'] },
|
||
{ label: 'การเตรียมข้อมูลล่วงหน้า', fields: ['อธิบายการทำความสะอาด การทำให้เป็นมาตรฐาน feature engineering'] },
|
||
{ label: 'การปฏิบัติตามความเป็นส่วนตัว', fields: ['[ ] ข้อมูลไม่ระบุตัวตน [ ] ได้รับความยินยอม [ ] DPIA ดำเนินการแล้ว [ ] ฐานทางกฎหมายบันทึกไว้'] },
|
||
],
|
||
},
|
||
{
|
||
title: '3. การประเมินอคติ (Bias assessment)',
|
||
content: [
|
||
'อธิบายการวิเคราะห์ที่ดำเนินการเพื่อระบุและบรรเทาอคติ (ประชากร วัฒนธรรม เพศ ชาติพันธุ์ ฯลฯ)',
|
||
'ระบุเมตริก fairness ที่ใช้และผลลัพธ์',
|
||
{ label: 'อคติที่ระบุ', fields: ['_____________________'] },
|
||
{ label: 'มาตรการบรรเทา', fields: ['_____________________'] },
|
||
{ label: 'ผ่านการทดสอบ fairness', fields: ['[ ] ใช่ [ ] ไม่ [ ] บางส่วน — อธิบาย: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: '4. การกำกับโดยมนุษย์',
|
||
content: [
|
||
{ label: 'ระดับอัตโนมัติ', fields: ['[ ] อัตโนมัติเต็ม [ ] Human-in-the-loop [ ] Human-on-the-loop [ ] คำแนะนำเท่านั้น'] },
|
||
{ label: 'กลไกการ override', fields: ['ผู้ใช้สามารถลบล้างการตัดสินใจของระบบได้อย่างไร?'] },
|
||
{ label: 'คำเตือนและข้อจำกัด', fields: ['คำเตือนใดที่แสดงแก่ผู้ใช้เกี่ยวกับข้อจำกัดของระบบ?'] },
|
||
],
|
||
},
|
||
{
|
||
title: '5. ความสามารถอธิบายและความโปร่งใส',
|
||
content: [
|
||
{ label: 'วิธี explainability', fields: ['[ ] SHAP [ ] LIME [ ] Feature importance [ ] Attention maps [ ] อื่นๆ: ___'] },
|
||
{ label: 'เอกสารสำหรับผู้ใช้', fields: ['อธิบายว่าการตัดสินใจถูกอธิบายแก่ผู้ใช้ปลายทางอย่างไร'] },
|
||
{ label: 'ข้อจำกัดที่สื่อสาร', fields: ['ข้อจำกัด ความแม่นยำ และขอบความผิดพลาดถูกสื่อสารอย่างไร?'] },
|
||
],
|
||
},
|
||
{
|
||
title: '6. การติดตามหลังปล่อย',
|
||
content: [
|
||
{ label: 'เมตริกที่ติดตาม', fields: ['ความแม่นยำ precision recall F1 drift detection fairness metrics ความหน่วง'] },
|
||
{ label: 'ความถี่การติดตาม', fields: ['[ ] ต่อเนื่อง [ ] รายวัน [ ] รายสัปดาห์ [ ] รายเดือน'] },
|
||
{ label: 'Alerting', fields: ['กำหนดเกณฑ์แจ้งเตือนสำหรับ drift และการลดลงของประสิทธิภาพ'] },
|
||
{ label: 'แผน rollback', fields: ['ขั้นตอนปิดใช้หรือแทนที่โมเดลในกรณีพฤติกรรมไม่คาดคิดหรือเป็นอันตราย'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. การประเมินความเสี่ยง',
|
||
content: [
|
||
{ label: 'ผลกระทบต่อสิทธิพื้นฐาน', fields: ['[ ] ต่ำ [ ] กลาง [ ] สูง — อธิบาย: ___'] },
|
||
{ label: 'ผลกระทบต่อสุขภาพหรือความปลอดภัย', fields: ['[ ] ไม่มี [ ] เป็นไปได้ [ ] โดยตรง — อธิบาย: ___'] },
|
||
{ label: 'ความเสี่ยงการเลือกปฏิบัติ', fields: ['[ ] ต่ำ [ ] กลาง [ ] สูง — อธิบาย: ___'] },
|
||
{ label: 'ความเสี่ยงความทึบ', fields: ['[ ] ต่ำ [ ] กลาง [ ] สูง — อธิบาย: ___'] },
|
||
],
|
||
},
|
||
{
|
||
title: '8. การอนุมัติ',
|
||
content: [
|
||
{ label: 'ผู้จัดทำ', fields: ['ชื่อ: ___ ลายเซ็น: ___ วันที่: ___'] },
|
||
{ label: 'CTO / ผู้รับผิดชอบเทคนิค', fields: ['ชื่อ: ___ ลายเซ็น: ___ วันที่: ___'] },
|
||
{ label: 'DPO / ผู้รับผิดชอบความเป็นส่วนตัว', fields: ['ชื่อ: ___ ลายเซ็น: ___ วันที่: ___'] },
|
||
{ label: 'Legal & Compliance', fields: ['ชื่อ: ___ ลายเซ็น: ___ วันที่: ___'] },
|
||
{ label: 'คณะกรรมการจริยธรรม (ถ้ามี)', fields: ['ความเห็น: ___ วันที่: ___'] },
|
||
],
|
||
},
|
||
],
|
||
},
|
||
{
|
||
id: 'piano-formazione',
|
||
heading: 'แผนการฝึกอบรม — ปฐมนิเทศ 90 วัน และการทบทวนประจำปี',
|
||
description: 'หลักสูตรบังคับสำหรับผู้ร่วมงาน: โมดูล ระยะเวลา บทบาทวิกฤต และทะเบียนการสำเร็จ',
|
||
intro:
|
||
'เอกสารปฏิบัติการเชื่อมกับหมวด 13 ของประมวลจริยธรรม HR เป็นเจ้าของแผน CISO DPO และ Legal จัดเนื้อหาโดเมน เก็บหลักฐานการสำเร็จในแฟ้มบุคลากร',
|
||
sections: [
|
||
{
|
||
title: '1. วัตถุประสงค์',
|
||
content: [
|
||
'ให้ผู้ร่วมงานทุกคนรู้จักประมวลจริยธรรม หน้าที่ด้านความปลอดภัยและความเป็นส่วนตัว และขอบเขตบทบาทต่อข้อมูล (แพลตฟอร์ม Legal Tech Health Tech)',
|
||
'ลดความเสี่ยงเชิงปฏิบัติการและกฎระเบียบใน 90 วันแรก และรักษาทักษะด้วยการทบทวนประจำปี',
|
||
'สร้างหลักฐานเอกสาร (ใบรับรอง แบบทดสอบ ทะเบียน) สำหรับการตรวจสอบและ KPI การฝึกอบรมที่เสร็จ',
|
||
],
|
||
},
|
||
{
|
||
title: '2. ผู้รับและหน้าที่',
|
||
content: [
|
||
{ label: 'ผู้ร่วมงานทั้งหมด', fields: ['ผู้ก่อตั้ง พนักงาน ที่ปรึกษา และผู้รับเหมาที่มีสิทธิเข้าถึงระบบหรือข้อมูล NexStudio'] },
|
||
{ label: 'เจ้าของแผน', fields: ['HR (ปฏิทิน ทะเบียน การเตือน)'] },
|
||
{ label: 'เจ้าของเนื้อหา', fields: ['CISO (ความปลอดภัย) DPO (ความเป็นส่วนตัว) Legal (ประมวล/compliance) CTO (secure coding / AI)'] },
|
||
{ label: 'ผู้จัดการสายงาน', fields: ['ตรวจสอบการสำเร็จตามกำหนด และรายงานความล่าช้าให้ HR'] },
|
||
],
|
||
},
|
||
{
|
||
title: '3. โมดูลบังคับ (core)',
|
||
content: [
|
||
{ label: 'M1 — ประมวลจริยธรรมและการประพฤติ', fields: ['ระยะเวลา: 1.5 ชม. เนื้อหา: คุณค่า ผลประโยชน์ทับซ้อน การรายงาน การลงโทษ ผลลัพธ์: ประกาศยอมรับลงนาม'] },
|
||
{ label: 'M2 — ความปลอดภัยสารสนเทศ', fields: ['ระยะเวลา: 2 ชม. เนื้อหา: phishing รหัสผ่าน/MFA การจำแนกข้อมูล อุปกรณ์ การรายงานเหตุการณ์ ผลลัพธ์: แบบทดสอบ ≥ 80%'] },
|
||
{ label: 'M3 — ความเป็นส่วนตัว PDPA และ GDPR', fields: ['ระยะเวลา: 2 ชม. เนื้อหา: ฐานทางกฎหมาย สิทธิเจ้าของข้อมูล การโอน การแจ้ง breach 72 ชม. บทบาทผู้ควบคุม/ผู้ประมวลผล ผลลัพธ์: แบบทดสอบ ≥ 80%'] },
|
||
{ label: 'M4 — ข้อมูลอ่อนไหวและขอบเขตผลิตภัณฑ์', fields: ['ระยะเวลา: 1.5 ชม. เนื้อหา: LexAura (ความลับวิชาชีพ) MediAura (ข้อมูลสุขภาพ) การลดข้อมูล การเข้าถึงพิเศษ ผลลัพธ์: เช็กลิสต์ความเข้าใจลงนาม'] },
|
||
{ label: 'M5 — การใช้ AI/ML อย่างรับผิดชอบ', fields: ['ระยะเวลา: 1.5 ชม. เนื้อหา: อคติ การกำกับโดยมนุษย์ ข้อจำกัดโมเดล ห้ามใช้ไม่สอดคล้อง ผลลัพธ์: แบบทดสอบ ≥ 80%'] },
|
||
{ label: 'M6 — การเขียนโค้ดอย่างปลอดภัยและการปล่อย (บทบาทเทคนิค)', fields: ['ระยะเวลา: 2 ชม. เนื้อหา: OWASP ความเสี่ยงหลัก การจัดการความลับ เช็กลิสต์ก่อนปล่อย SBOM บังคับสำหรับนักพัฒนา DevOps QA ผลลัพธ์: แบบทดสอบ ≥ 80% + แบบฝึกเช็กลิสต์'] },
|
||
],
|
||
},
|
||
{
|
||
title: '4. ปฏิทินปฐมนิเทศ 90 วัน',
|
||
content: [
|
||
{ label: 'วัน 0–7 (สัปดาห์ 1)', fields: ['M1 ประมวลจริยธรรม + ลงนามยอมรับและ NDA หากใช้ได้ เข้าถึงระบบหลัง MFA และบรีฟความปลอดภัยพื้นฐาน (ส่วนของ M2)'] },
|
||
{ label: 'วัน 8–30 (เดือน 1)', fields: ['M2 ความปลอดภัยครบ + M3 ความเป็นส่วนตัว ห้ามเข้าถึงข้อมูล production โดยไม่มี M2/M3 เสร็จ'] },
|
||
{ label: 'วัน 31–60 (เดือน 2)', fields: ['M4 ขอบเขตผลิตภัณฑ์ (LexAura/MediAura ตามบทบาท) + M5 AI บทบาทเทคนิค: เริ่ม M6'] },
|
||
{ label: 'วัน 61–90 (เดือน 3)', fields: ['ทำ M6 ให้เสร็จ (ถ้าต้อง) ทบทวนกับผู้จัดการ: ช่องว่าง การอบรมเพิ่ม ยืนยันทะเบียน จุดตรวจ HR: โมดูลบังคับของบทบาทครบ 100%'] },
|
||
],
|
||
note: 'กำหนดตายตัว: ยอมรับภายใน 7 วัน core M2–M5 ภายใน 60 วัน M6 ภายใน 90 วันสำหรับบทบาทเทคนิค ล่าช้า > 14 วัน: escalate ไป HR และผู้จัดการ อาจจำกัดการเข้าถึง',
|
||
},
|
||
{
|
||
title: '5. การฝึกอบรมประจำปี',
|
||
content: [
|
||
'ทบทวนบังคับภายใน 12 เดือนนับจากการสำเร็จครั้งก่อน (หรือวันปฐมนิเทศ)',
|
||
'ระยะเวลารวมขั้นต่ำ: 3 ชั่วโมง (M1 อัปเดต + ส่วนต่างกฎ M2/M3 + ทบทวน AI)',
|
||
'ตัวกระตุ้นเพิ่ม: การเปลี่ยนกฎสำคัญ เหตุการณ์ร้ายแรง ขอบเขตผลิตภัณฑ์ใหม่ การเปลี่ยนบทบาทวิกฤต',
|
||
'รูปแบบที่ยอมรับ: เซสชันสด e-learning พร้อมแบบทดสอบ หรือเวิร์กช็อปภายในที่มีเอกสาร',
|
||
],
|
||
},
|
||
{
|
||
title: '6. การฝึกอบรมเพิ่มสำหรับบทบาทวิกฤต',
|
||
content: [
|
||
{ label: 'CISO / ความปลอดภัย', fields: ['playbook ตอบสนองเหตุการณ์ tabletop ประจำปี threat modeling'] },
|
||
{ label: 'DPO / ความเป็นส่วนตัว', fields: ['เวิร์กช็อป DPIA สิทธิเจ้าของข้อมูล การโอนระหว่างประเทศ'] },
|
||
{ label: 'Legal & compliance', fields: ['อัปเดตกฎ LexAura/MediAura สัญญาผู้ประมวลผลช่วง'] },
|
||
{ label: 'วิศวกรรม / DevOps', fields: ['Secure SDLC ขั้นสูง ทบทวน SBOM walkthrough ผลการ penetration test'] },
|
||
{ label: 'สนับสนุน / customer success', fields: ['สิทธิ์น้อยสุดบนข้อมูลลูกค้า สคริปต์ escalate ห้ามใช้ นอกตั๋ว'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. รูปแบบการจัดและสื่อ',
|
||
content: [
|
||
'ภาษา: อิตาลี อังกฤษ ไทย (สอดคล้องกับเว็บไซต์และประมวลจริยธรรม)',
|
||
'สื่อ: สไลด์/วิดีโอภายใน ประมวลฉบับปัจจุบัน ภาคผนวกปฏิบัติการ (เช็กลิสต์ DPIA AI impact)',
|
||
'การประเมิน: แบบทดสอบหลายตัวเลือก (เกณฑ์ 80%) หรือใบยืนยันการเข้าร่วม + แบบฝึกสำหรับเวิร์กช็อป',
|
||
'สอบใหม่: หากไม่ผ่าน สอบใหม่ภายใน 14 วันพร้อม mentoring จากเจ้าของโดเมน',
|
||
],
|
||
},
|
||
{
|
||
title: '8. ทะเบียนการฝึกอบรม (เทมเพลตแถว)',
|
||
content: [
|
||
{
|
||
label: 'ฟิลด์บังคับต่อรายการ',
|
||
fields: [
|
||
'ชื่อผู้ร่วมงาน',
|
||
'บทบาท',
|
||
'โมดูล (M1–M6 / ประจำปี / วิกฤต)',
|
||
'วันที่',
|
||
'ระยะเวลา (ชม.)',
|
||
'ผล (ผ่าน / ต้องสอบใหม่)',
|
||
'หลักฐาน (ลิงก์แบบทดสอบ / PDF / ลายเซ็น)',
|
||
'ผู้ตรวจสอบ',
|
||
],
|
||
},
|
||
],
|
||
note: 'ระยะเวลาเก็บทะเบียน: ตามนโยบายการเก็บรักษา (บันทึกการฝึกอบรมและประกาศยอมรับ) รูปแบบแนะนำ: ชีตแชร์หรือ HRIS พร้อม export สำหรับ audit',
|
||
},
|
||
{
|
||
title: '9. KPI และการควบคุม',
|
||
content: [
|
||
'% ปฐมนิเทศที่โมดูลบังคับเสร็จภายใน 90 วัน (เป้า ≥ 95%)',
|
||
'% บุคลากรที่ทบทวนประจำปีครบ (เป้า ≥ 95%)',
|
||
'เวลาเฉลี่ยในการทำ M1–M5 ให้เสร็จ',
|
||
'จำนวนความล่าช้า > 14 วัน และการแก้ไข',
|
||
],
|
||
},
|
||
],
|
||
footer: 'การอนุมัติแผน: HR _______ · CISO _______ · DPO _______ · วันที่ _______',
|
||
},
|
||
{
|
||
id: 'security-disclosure',
|
||
heading: 'นโยบาย responsible disclosure และการรายงานช่องโหว่',
|
||
description: 'วิธีรายงานช่องโหว่ความปลอดภัยถึง NexStudio: ช่องทาง เวลาตอบสนอง ขอบเขต และกฎสุจริต (soft bug bounty)',
|
||
intro:
|
||
'เอกสารปฏิบัติการเชื่อมกับหมวด 11 ของประมวลจริยธรรม (การจัดการช่องโหว่) ช่องทางอย่างเป็นทางการ: security@nexstudio.com โปรแกรม bug bounty ที่มีรางวัลเงินอาจเพิ่มภายหลังโดยไม่เปลี่ยนช่องทางนี้',
|
||
sections: [
|
||
{
|
||
title: '1. วัตถุประสงค์',
|
||
content: [
|
||
'ให้ผู้วิจัยและผู้ใช้รายงานช่องโหว่โดยสุจริต พร้อมเวลาตอบสนองที่กำหนด และไม่เสี่ยงต่อการดำเนินคดีหากปฏิบัติตามนโยบายนี้',
|
||
'ปกป้องข้อมูลลูกค้า ผู้ป่วย และสำนักงาน (LexAura / MediAura) และความพร้อมใช้ของบริการ SaaS',
|
||
],
|
||
},
|
||
{
|
||
title: '2. ขอบเขต (in scope)',
|
||
content: [
|
||
'เว็บไซต์และเว็บแอปสาธารณะของ NexStudio (โดเมนหลักและหน้า IT/EN/TH)',
|
||
'API และ endpoint ที่ต้องยืนยันตัวตนของ LexAura และ MediAura ใน production หรือ staging สาธารณะ',
|
||
'โครงสร้างคลาวด์ที่เป็นของ NexStudio โดยตรงและเข้าถึงได้จากอินเทอร์เน็ต',
|
||
'การตั้งค่าผิดพลาดที่เปิดเผยข้อมูลส่วนบุคคล ความลับ สำรอง หรือแผงผู้ดูแล',
|
||
],
|
||
},
|
||
{
|
||
title: '3. นอกขอบเขต (out of scope)',
|
||
content: [
|
||
'DoS/DDoS การ flood การทดสอบความเครียดโดยไม่ประสาน',
|
||
'Social engineering ต่อพนักงาน ลูกค้า หรือผู้ให้บริการ (phishing pretexting)',
|
||
'สแปม การส่งมัลแวร์ ความปลอดภัยทางกายภาพ',
|
||
'ช่องโหว่ของผลิตภัณฑ์บุคคลที่สามที่ NexStudio ไม่ได้ดำเนินการ เว้นแต่เกิดจากการตั้งค่าผิดของเรา',
|
||
'รายงานจากสแกนเนอร์อย่างเดียวโดยไม่มี PoC ที่ทำซ้ำได้',
|
||
'ประเด็นที่ทราบแล้วและอยู่ระหว่าง remediation',
|
||
],
|
||
},
|
||
{
|
||
title: '4. กฎการทดสอบโดยสุจริต',
|
||
content: [
|
||
'อย่าเข้าถึง แก้ไข หรือลบข้อมูลของบุคคลที่สามเกินกว่าที่จำเป็นเพื่อพิสูจน์ปัญหา',
|
||
'หยุดทันทีหากพบข้อมูลส่วนบุคคลหรือสุขภาพจริง; รายงานโดยไม่นำข้อมูลออก',
|
||
'อย่ารัน exploit ที่ทำให้บริการแย่ลงหรือกระทบผู้ใช้อื่น',
|
||
'อย่าเรียกค่าไถ่หรือเปิดเผยสาธารณะก่อนประสาน (embargo ที่สมเหตุสมผล)',
|
||
'ใช้บัญชีทดสอบของตนเองหรือ staging เมื่อมี',
|
||
],
|
||
},
|
||
{
|
||
title: '5. วิธีรายงาน',
|
||
content: [
|
||
{ label: 'ช่องทาง', fields: ['อีเมล: security@nexstudio.com (PGP เป็นทางเลือกในภายหลังหากเผยแพร่)'] },
|
||
{
|
||
label: 'เนื้อหาขั้นต่ำของรายงาน',
|
||
fields: [
|
||
'ชื่อเรื่องสั้น',
|
||
'URL / endpoint / ส่วนประกอบ',
|
||
'คำอธิบายและผลกระทบ',
|
||
'ขั้นตอนทำซ้ำ (PoC)',
|
||
'ความรุนแรงโดยประมาณ (Low/Medium/High/Critical)',
|
||
'ช่องทางติดต่อติดตาม',
|
||
'หากเห็นข้อมูล: หมวดหมู่และปริมาณ (อย่าแนบข้อมูลจริง)',
|
||
],
|
||
},
|
||
],
|
||
note: 'หัวข้อแนะนำ: [SECURITY] ชื่อสั้น อย่าแนบ dump ของข้อมูลจริง',
|
||
},
|
||
{
|
||
title: '6. SLA การตอบสนองและการแก้ไข',
|
||
content: [
|
||
{ label: 'Ack (รับเรื่อง)', fields: ['ภายใน 72 ชั่วโมงทำการนับจากรายงานที่ถูกต้อง'] },
|
||
{ label: 'Triage เบื้องต้น', fields: ['ภายใน 5 วันทำการ: ยืนยัน in/out of scope และความรุนแรงเบื้องต้น'] },
|
||
{
|
||
label: 'เป้าหมายการแก้ไข (โดยประมาณ)',
|
||
fields: [
|
||
'Critical: กักกันทันที; แก้หรือบรรเทาภายใน 7 วัน',
|
||
'High: 14 วัน',
|
||
'Medium: 30 วัน',
|
||
'Low: 90 วัน หรือรอบปล่อยถัดไป',
|
||
],
|
||
},
|
||
{ label: 'การสื่อสาร', fields: ['อัปเดตผู้รายงานจนปิดเรื่อง; advisory สาธารณะหลังแก้ หากขอเครดิต'] },
|
||
],
|
||
},
|
||
{
|
||
title: '7. Safe harbor',
|
||
content: [
|
||
'NexStudio จะไม่ดำเนินคดีกับผู้ที่รายงานโดยสุจริตและปฏิบัติตามนโยบายนี้กับกฎหมายที่ใช้บังคับ',
|
||
'Safe harbor ไม่ครอบคลุมกิจกรรมนอกขอบเขต การขโมยข้อมูล การขู่กรรโชก หรือความเสียหายโดยเจตนา',
|
||
],
|
||
},
|
||
{
|
||
title: '8. การยอมรับและ bug bounty',
|
||
content: [
|
||
'ระยะปัจจุบัน (soft bounty): คำขอบคุณเป็นลายลักษณ์อักษร และหากผู้รายงานยินยอม ระบุชื่อใน hall of fame / advisory',
|
||
'รางวัลเงินหรือของที่ระลึก: ไม่รับประกัน; อาจมีภายหลังพร้อมตารางสาธารณะโดยไม่เปลี่ยนช่องทาง security@',
|
||
'รายการซ้ำและนอกขอบเขต: ack สุภาพโดยไม่มีรางวัล',
|
||
],
|
||
},
|
||
{
|
||
title: '9. ผู้รับผิดชอบภายใน',
|
||
content: [
|
||
{ label: 'CISO / Security', fields: ['Triage การแก้ไข การสื่อสารกับผู้รายงาน'] },
|
||
{ label: 'DPO', fields: ['เกี่ยวข้องหากช่องโหว่เกี่ยวกับข้อมูลส่วนบุคคลหรือ breach'] },
|
||
{ label: 'Legal', fields: ['ประเมิน safe harbor และการเปิดเผยสาธารณะ'] },
|
||
{ label: 'CTO', fields: ['ลำดับความสำคัญทางเทคนิคและทรัพยากรแก้ไข'] },
|
||
],
|
||
},
|
||
],
|
||
footer: 'การอนุมัตินโยบาย: CISO _______ · CTO _______ · Legal _______ · วันที่ _______',
|
||
},
|
||
],
|
||
},
|
||
};
|
||
|
||
export function getAllegatiCodiceEtico(locale: SupportedLocale) {
|
||
return allegatiByLocale[locale];
|
||
}
|