IT Department

Information Security Department System

An infosec team protecting company systems and data through policies, assessments, awareness, and incident response.

From drafting policy to containing incidents, with employee awareness and periodic risk reporting to management.

No credit card required — your project is set up with the full system in under a minute

Policy1
Log existing security policies and flag the outdated ones
Assessment1
Schedule the next periodic vulnerability assessment
Incident0
No cards yet
Response0
No cards yet
Awareness1
Launch the first anti-phishing awareness campaign
Report0
No cards yet

This is the system board as you'll receive it: workflow columns and starter cards showing the first steps

How does work flow in this system?

Work starts with drafting policies: a card in “Policy” for every required security control — passwords, access rights, backups — drafted, approved, and updated periodically. Periodic assessments and penetration tests are managed as cards in “Assessment” with their results, discovered vulnerabilities, and each one's severity. When a security incident is detected, a card is created in “Incident” with its severity and scope classification; it moves to “Response” for containment, then eradication, then recovery, with lessons learned documented on the card. Employee awareness programs are managed as cards in “Awareness,” and risk and compliance summaries go to management from “Report.”

Chat is for quick coordination within the team during response, with a strict ban on sharing details of vulnerabilities or ongoing incidents in it. The Forum documents approved policies, post-containment incident analyses, and risk assessment discussions. Announcements reach all employees: awareness circulars, alerts on active phishing campaigns, and mandatory password updates. Dues manages security spending: protection tools, external penetration tests, and specialized courses.

Security engineers run the assessments and report vulnerabilities ranked by severity; the security officer approves remediation priorities, drafts policies, and leads response to major incidents. Risk reports are presented to management periodically, and every major incident triggers a review of an existing policy or the launch of a new awareness program that becomes a card in its proper column.

Who does what?

The operational roles in this system and each role's responsibility in daily work — assign them to your team as-is or adapt them to your reality.

Information Security Officer

Approves policies and prioritizes vulnerability remediation by severity, leads response to major incidents, and raises risk reports to management.

Security Engineers

Run assessments and penetration tests, respond to incidents through containment, eradication, and recovery, and document every incident with its lessons.

Security Awareness Coordinator

Builds employee awareness programs and measures their response, publishing security alerts and circulars in Announcements as soon as they're approved.

What's prepared for you from day one?

System units

  • Tasks A kanban board with workflow columns and execution cards
  • Chat The team's fast daily coordination channel
  • Forum Documented discussions in organized sections — decisions and knowledge that never get lost
  • Announcements The official voice of management — circulars and alerts that reach everyone
  • Dues Internal money with strict privacy — dues, advances, and expenses

Forum sections (4)

  • Approved Policies & ControlsApproved security policy texts and their update history — the official reference invoked in any dispute.
  • Incident Analysis & LessonsDocumenting the aftermath of every security incident: what happened, how we contained it, and what prevents recurrence.
  • Vulnerabilities & RisksDiscussing discovered vulnerabilities, rating their severity, and planning remediation before turning them into execution cards.
  • Awareness & ComplianceAwareness materials, campaign plans, and measuring employee compliance with security controls.

«Working Rules for This System» — Pinned in the forum

1. Details of vulnerabilities and ongoing incidents are never shared in Chat — only on a restricted card or a limited forum topic. 2. Every security incident is logged as a card the moment it's detected, whatever its size. 3. No policy is applied before it's approved and documented in the “Approved Policies & Controls” section. 4. Every assessment's results are recorded on its card within one business day of completion. 5. Phishing alerts and general warnings are published in Announcements as soon as they're verified. 6. Security tool and testing expenses are recorded in Dues while keeping their details confidential.

Welcome announcement: «Information Security Team's Working System»

This system is how we work from today: policies are drafted and approved here, assessments are tracked as cards with their results, incidents are managed from “Incident” to “Response” with full documentation, and awareness reaches employees via Announcements. Remember: details of vulnerabilities and ongoing incidents are never shared in Chat. First step: log existing policies as cards in the “Policy” column and mark which need updating.

Ready? Your first project is two minutes away

Create your free workspace now, and invite your team before the day is over.