Appearance
Onboarding Security Training Checklist
Purpose: Ensure every new employee, contractor, or Business Associate receives the security training, access, and tooling required to work safely with Cirius Group systems before they touch ePHI. Supports HIPAA §164.308(a)(5) (awareness and training), §164.308(a)(3) (workforce security), and SOC2 CC1.4.
Owner: Rory (Security Officer) with Adriana (training completion tracking) Audience: Hiring manager, HR, new hire, Security Officer Review cadence: Annual — refreshed every December as controls and tooling evolve Target timeline: Start on Day -5 before first day of work; complete all items by end of Day 5
How to use
- Hiring manager opens a SecOps story with
category=onboardingon the day an offer is signed. The story owner is the new hire's manager. - Each checkbox below is an auditable step. Do NOT grant ePHI access until steps 1–11 are signed off.
- The new hire's signed acknowledgments are filed in
SharePoint → HR → Onboarding → <name> → <YYYY-MM-DD>/. - On completion, attach the SharePoint folder URL to the SecOps story and transition it to CLOSED.
Pre-start (Day -5 to Day -1)
- [ ] Background check cleared — HR confirms results (referenced in
hipaa-administrative-procedures.md§3.2) - [ ] Employment agreement signed — includes confidentiality, acceptable use, reporting obligations
- [ ] HIPAA awareness attestation signed — acknowledges Security Rule and Privacy Rule obligations
- [ ] Device decision — corporate-issued Intune-enrolled laptop OR approved BYOD path (BYOD requires additional device certificate and Intune MAM)
Day 1 — Identity and authentication
- [ ] Entra ID account provisioned — ciriusgroup.com (and ciriusdde.com if role requires DDE access)
- [ ] MFA enrolled — Microsoft Authenticator app registered. Preference for phone app; hardware token (FIDO2) issued for privileged roles once available (see risk-acceptance-register.md)
- [ ] Entra password set — minimum 14 characters, no reuse of last 24, no common-dictionary entries
- [ ] Group memberships applied — role-mapped security groups only; no Global Admin or PIM-eligible role granted on Day 1
- [ ] Conditional Access policies verified — new hire tested end-to-end on a pre-prod policy set; confirmed CA applies on first real sign-in
Day 1 — Remote access and endpoint
- [ ] Twingate client installed — configured, client device identified, connector confirmed. (Primary remote access path.)
- [ ] GlobalProtect access — only for CEO/CTO profile; standard staff do NOT get GlobalProtect
- [ ] Device enrolled in Intune — compliance policy applies within 30 minutes of enrollment
- [ ] Cortex XDR agent verified — agent status "Protected" in Cortex console for the new device
- [ ] Full-disk encryption verified — BitLocker (Windows) or FileVault (macOS) enabled with escrow key in Intune
Day 2 — Password and credential management
- [ ] Keeper Security account provisioned — shared vault access assigned per role. No shared spreadsheets or documents with passwords — ever.
- [ ] Keeper training completed — 20-minute video; acknowledgement signed
- [ ] Password manager adoption confirmed — new hire creates three records in first week; Rory spot-checks
Day 2–3 — Awareness and training
- [ ] HIPAA Security Rule training completed — KnowBe4 course, ≥80% passing score
- [ ] Privacy Rule + Breach Notification training completed — KnowBe4 course
- [ ] Phishing simulation baseline — new hire included in next monthly simulation cohort
- [ ] Acceptable Use Policy signed — file in SharePoint HR folder
- [ ] Clean-desk policy acknowledged — physical workstation hygiene; do not leave laptop unattended with PHI on screen
- [ ] Incident reporting orientation — new hire watches 10-minute walkthrough of
runbooks/incident-response.mdand knows how to contact the Security Officer
Day 3 — Break-glass and emergency procedures
- [ ] Break-glass account awareness briefing — every workforce member knows break-glass accounts exist, that they are NEVER to be used except under declared emergency, and that any use produces a CRITICAL alert in SecOps. The 18 break-glass accounts are enumerated briefly so the new hire recognizes the names.
- [ ] Reporting obligation acknowledgment — new hire signs: "I will report suspected security incidents immediately to the Security Officer by phone or SecOps."
- [ ] Emergency contact tree reviewed — Security Officer, DR admins (Kevin, Greg), Adriana for breach notification
Day 4–5 — Tooling and data access
- [ ] SharePoint access scoped — only document libraries the new hire's role requires; no blanket Everyone access
- [ ] SecOps platform access — read-only by default; escalation to writer requires Security Officer approval
- [ ] Source code access (GitHub org
Cirius-Group-Inc) — SHA-pinning awareness training completed if the role touches GitHub Actions - [ ] psql-secops-prod access — NO direct database access granted at onboarding. If ever needed, requires dedicated access review and just-in-time provisioning via Keeper PAM session recording.
- [ ] AWS console access — only if role requires; SSO via Entra; no IAM users, no long-lived access keys
- [ ] Cortex XDR console access — only if security role; read-only unless explicit need
- [ ] Arctic Wolf portal access — only Security Officer and designated IT staff
End of Week 1 — Confirmation
- [ ] Hiring manager confirms — all checklist items above are complete
- [ ] Security Officer signs off — verifies that access granted matches role
- [ ] SecOps story closed — with SharePoint folder URL attached
Day 30 check-in
- [ ] Access recertification — confirm access is still appropriate after 30 days; remove any access not actively used
- [ ] Training quiz refresher — 10-minute scenario quiz; remediation if score < 80%
Day 90 check-in
- [ ] Phishing simulation result reviewed — new hire's response to first two simulations documented; coaching if failed
- [ ] Incident reporting confirmation — has the new hire reported anything suspicious? If not, a short conversation covers what they're seeing
Special cases
Contractors
- Limited-term access with an explicit end date set in Entra (account auto-expires)
- No SecOps writer access unless justified in writing
- Terminate per
hipaa-administrative-procedures.md§3.3 when contract ends
Privileged roles (Domain Admin, Global Admin, PIM Privileged Role Admin)
- All standard checklist items PLUS:
- FIDO2 hardware key issued and tested (once available — see risk-acceptance-register.md)
- Keeper PAM session recording configured for all target systems
- Quarterly admin-account hygiene review per
runbooks/admin-account-hygiene.md
Business Associates
- Onboarding via BAA workflow (Adriana owner) in addition to this checklist
- Vendor added to
compliance/vendor-risk-inventory.md
Document history
| Date | Change | Author |
|---|---|---|
| April 2026 | Initial onboarding security checklist | Kobe |