import datetime from docx import Document from docx2pdf import convert def create_assessment_doc(data): """Creates a Word document from the assessment data.""" document = Document() document.add_heading('Software/Vendor Security Assessment Request', 0) # 1. Requestor Information document.add_heading('1. Requestor Information', level=1) document.add_paragraph(f"Name: {data['requestor_name']}") document.add_paragraph(f"Department: {data['department']}") document.add_paragraph(f"Email Address: {data['email']}") document.add_paragraph(f"Phone Number: {data['phone']}") # 2. Request Type document.add_heading('2. Request Type', level=1) document.add_paragraph(data['request_type']) # 3. Deployment Model document.add_heading('3. Deployment Model', level=1) document.add_paragraph(data['deployment_model']) # 4. Software/Vendor Information document.add_heading('4. Software/Vendor Information', level=1) document.add_paragraph(f"Software/Vendor Name: {data['vendor_name']}") document.add_paragraph(f"Software Name: {data['software_name']}") document.add_paragraph(f"Software/Vendor Website: {data['vendor_website']}") document.add_paragraph(f"Software/Vendor Contact Information: {data['vendor_contact']}") document.add_paragraph(f"Brief Description of Software/Vendor and its Purpose: {data['vendor_description']}") # 5. Intended Use document.add_heading('5. Intended Use', level=1) document.add_paragraph(f"Describe how the software/vendor will be used within the company: {data['intended_use']}") document.add_paragraph(f"Specify the departments or teams that will be using the software/vendor: {data['departments_teams']}") document.add_paragraph(f"Identify any critical business processes or data that will be impacted by the software/vendor: {data['critical_processes_data']}") # 6. Prerequisites document.add_heading('6. Prerequisites', level=1) document.add_paragraph(f"Operating System Requirements: {data['os_requirements']}") document.add_paragraph(f"Hardware Requirements (e.g., RAM, storage space): {data['hardware_requirements']}") document.add_paragraph(f"Network Connectivity (e.g., bandwidth, VPN): {data['network_connectivity']}") document.add_paragraph(f"Software Dependencies (e.g., libraries, frameworks): {data['software_dependencies']}") document.add_paragraph(f"User Access Requirements (e.g., specific roles, permissions): {data['user_access_requirements']}") document.add_paragraph(f"Other Prerequisites: {data['other_prerequisites']}") # 7. Technical Information document.add_heading('7. Technical Information', level=1) document.add_paragraph(f"Hosting Environment (e.g., cloud provider, on-premise data center): {data['hosting_environment']}") document.add_paragraph(f"Network Requirements (e.g., ports, protocols, firewall rules): {data['network_requirements']}") document.add_paragraph(f"Data Storage Requirements (e.g., location, encryption, data retention policies): {data['data_storage_requirements']}") document.add_paragraph(f"Integration with Existing Systems (if any): {data['integration_existing_systems']}") document.add_paragraph(f"API Information (if applicable): {data['api_information']}") # 8. Security Requirements document.add_heading('8. Security Requirements', level=1) document.add_paragraph(f"Data Security - How will data be protected in transit and at rest?: {data['data_protection']}") document.add_paragraph(f"Data Security - Does the software/vendor comply with relevant data privacy regulations (e.g., GDPR, CCPA)?: {data['data_privacy_compliance']}") document.add_paragraph(f"Data Security - What data encryption methods are used?: {data['data_encryption_methods']}") document.add_paragraph(f"Access Control - How will access to the software/vendor be granted and managed?: {data['access_control_management']}") document.add_paragraph(f"Access Control - Does the software/vendor support multi-factor authentication?: {data['multi_factor_authentication']}") document.add_paragraph(f"Access Control - What user roles and permissions are available?: {data['user_roles_permissions']}") document.add_paragraph(f"Vulnerability Management - Does the software/vendor have a vulnerability disclosure program?: {data['vulnerability_disclosure']}") document.add_paragraph(f"Vulnerability Management - How are security patches and updates managed?: {data['security_patch_management']}") document.add_paragraph(f"Vulnerability Management - Are regular security assessments and penetration testing conducted?: {data['security_assessments']}") document.add_paragraph(f"Compliance - Does the software/vendor comply with relevant industry security standards (e.g., ISO 27001, SOC 2)?: {data['industry_security_standards']}") document.add_paragraph(f"Compliance - Are there any third-party security certifications or audits available?: {data['third_party_certifications']}") document.add_paragraph(f"Business Continuity and Disaster Recovery - What are the software/vendor's business continuity and disaster recovery plans?: {data['business_continuity_plans']}") document.add_paragraph(f"Business Continuity and Disaster Recovery - What are the recovery time objectives (RTOs) and recovery point objectives (RPOs)?: {data['rto_rpo']}") # 9. Privacy Requirements document.add_heading('9. Privacy Requirements', level=1) document.add_paragraph(f"Data Collection - What personal data will be collected by the software/vendor?: {data['personal_data_collected']}") document.add_paragraph(f"Data Collection - What is the purpose of collecting this data?: {data['data_collection_purpose']}") document.add_paragraph(f"Data Collection - Will data be shared with third parties? If so, with whom and for what purpose?: {data['data_sharing']}") document.add_paragraph(f"Data Subject Rights - How does the software/vendor ensure data subject rights (e.g., access, rectification, erasure)?: {data['data_subject_rights']}") document.add_paragraph(f"Data Subject Rights - Does the software/vendor provide a privacy policy that is readily accessible to users?: {data['privacy_policy']}") # 10. Legal and Contractual Requirements document.add_heading('10. Legal and Contractual Requirements', level=1) document.add_paragraph(f"Software License Agreement: {data['license_agreement']}") document.add_paragraph(f"Service Level Agreement (SLA): {data['sla']}") document.add_paragraph(f"Data Processing Agreement (DPA): {data['dpa']}") document.add_paragraph(f"Vendor Security Policies: {data['vendor_security_policies']}") # 11. Risk Assessment document.add_heading('11. Risk Assessment', level=1) document.add_paragraph(f"Identify any potential security or privacy risks associated with the use of the software/vendor: {data['potential_risks']}") document.add_paragraph(f"Describe the risk mitigation measures that will be implemented: {data['risk_mitigation']}") # 12. Approval (This section will likely be filled later) document.add_heading('12. Approval', level=1) document.add_paragraph("Security Analyst Review:") document.add_paragraph("Date of Review: ") document.add_paragraph("Security Analyst Name: ") document.add_paragraph("Security Assessment Findings: ") document.add_paragraph("Approval Status (Approved, Conditionally Approved, Rejected): ") document.add_paragraph("Management Approval (if required):") document.add_paragraph("Date of Approval: ") document.add_paragraph("Approving Manager Name: ") # 13. Supporting Documentation document.add_heading('13. Supporting Documentation', level=1) document.add_paragraph("Attach any relevant supporting documentation, such as:") document.add_paragraph("Vendor security questionnaires") document.add_paragraph("Penetration testing reports") document.add_paragraph("Security audit reports") document.add_paragraph("Privacy impact assessments") return document def create_markdown_file(data, md_filename): # Receive filename as argument """Creates a Markdown file from the assessment data.""" with open(md_filename, "w") as f: # Use the provided filename # Add all the headings and data from the form in Markdown format f.write("# Software/Vendor Security Assessment Request\n\n") f.write("## 1. Requestor Information\n") f.write(f"Name: {data['requestor_name']}\n") f.write(f"Department: {data['department']}\n") f.write(f"Email Address: {data['email']}\n") f.write(f"Phone Number: {data['phone']}\n") f.write("\n## 2. Request Type\n") f.write(f"{data['request_type']}\n") f.write("\n## 3. Deployment Model\n") f.write(f"{data['deployment_model']}\n") f.write("\n## 4. Software/Vendor Information\n") f.write(f"Software/Vendor Name: {data['vendor_name']}\n") f.write(f"Software Name: {data['software_name']}\n") f.write(f"Software/Vendor Website: {data['vendor_website']}\n") f.write(f"Software/Vendor Contact Information: {data['vendor_contact']}\n") f.write(f"Brief Description of Software/Vendor and its Purpose: {data['vendor_description']}\n") f.write("\n## 5. Intended Use\n") f.write(f"Describe how the software/vendor will be used within the company: {data['intended_use']}\n") f.write(f"Specify the departments or teams that will be using the software/vendor: {data['departments_teams']}\n") f.write(f"Identify any critical business processes or data that will be impacted by the software/vendor: {data['critical_processes_data']}\n") f.write("\n## 6. Prerequisites\n") f.write(f"Operating System Requirements: {data['os_requirements']}\n") f.write(f"Hardware Requirements (e.g., RAM, storage space): {data['hardware_requirements']}\n") f.write(f"Network Connectivity (e.g., bandwidth, VPN): {data['network_connectivity']}\n") f.write(f"Software Dependencies (e.g., libraries, frameworks): {data['software_dependencies']}\n") f.write(f"User Access Requirements (e.g., specific roles, permissions): {data['user_access_requirements']}\n") f.write(f"Other Prerequisites: {data['other_prerequisites']}\n") f.write("\n## 7. Technical Information\n") f.write(f"Hosting Environment (e.g., cloud provider, on-premise data center): {data['hosting_environment']}\n") f.write(f"Network Requirements (e.g., ports, protocols, firewall rules): {data['network_requirements']}\n") f.write(f"Data Storage Requirements (e.g., location, encryption, data retention policies): {data['data_storage_requirements']}\n") f.write(f"Integration with Existing Systems (if any): {data['integration_existing_systems']}\n") f.write(f"API Information (if applicable): {data['api_information']}\n") f.write("\n## 8. Security Requirements\n") f.write(f"Data Security - How will data be protected in transit and at rest?: {data['data_protection']}\n") f.write(f"Data Security - Does the software/vendor comply with relevant data privacy regulations (e.g., GDPR, CCPA)?: {data['data_privacy_compliance']}\n") f.write(f"Data Security - What data encryption methods are used?: {data['data_encryption_methods']}\n") f.write(f"Access Control - How will access to the software/vendor be granted and managed?: {data['access_control_management']}\n") f.write(f"Access Control - Does the software/vendor support multi-factor authentication?: {data['multi_factor_authentication']}\n") f.write(f"Access Control - What user roles and permissions are available?: {data['user_roles_permissions']}\n") f.write(f"Vulnerability Management - Does the software/vendor have a vulnerability disclosure program?: {data['vulnerability_disclosure']}\n") f.write(f"Vulnerability Management - How are security patches and updates managed?: {data['security_patch_management']}\n") f.write(f"Vulnerability Management - Are regular security assessments and penetration testing conducted?: {data['security_assessments']}\n") f.write(f"Compliance - Does the software/vendor comply with relevant industry security standards (e.g., ISO 27001, SOC 2)?: {data['industry_security_standards']}\n") f.write(f"Compliance - Are there any third-party security certifications or audits available?: {data['third_party_certifications']}\n") f.write(f"Business Continuity and Disaster Recovery - What are the software/vendor's business continuity and disaster recovery plans?: {data['business_continuity_plans']}\n") f.write(f"Business Continuity and Disaster Recovery - What are the recovery time objectives (RTOs) and recovery point objectives (RPOs)?: {data['rto_rpo']}\n") f.write("\n## 9. Privacy Requirements\n") f.write(f"Data Collection - What personal data will be collected by the software/vendor?: {data['personal_data_collected']}\n") f.write(f"Data Collection - What is the purpose of collecting this data?: {data['data_collection_purpose']}\n") f.write(f"Data Collection - Will data be shared with third parties? If so, with whom and for what purpose?: {data['data_sharing']}\n") f.write(f"Data Subject Rights - How does the software/vendor ensure data subject rights (e.g., access, rectification, erasure)?: {data['data_subject_rights']}\n") f.write(f"Data Subject Rights - Does the software/vendor provide a privacy policy that is readily accessible to users?: {data['privacy_policy']}\n") f.write("\n## 10. Legal and Contractual Requirements\n") f.write(f"Software License Agreement: {data['license_agreement']}\n") f.write(f"Service Level Agreement (SLA): {data['sla']}\n") f.write(f"Data Processing Agreement (DPA): {data['dpa']}\n") f.write(f"Vendor Security Policies: {data['vendor_security_policies']}\n") f.write("\n## 11. Risk Assessment\n") f.write(f"Identify any potential security or privacy risks associated with the use of the software/vendor: {data['potential_risks']}\n") f.write(f"Describe the risk mitigation measures that will be implemented: {data['risk_mitigation']}\n") f.write("\n## 12. Approval\n") f.write("Security Analyst Review:\n") f.write("Date of Review: \n") f.write("Security Analyst Name: \n") f.write("Security Assessment Findings: \n") f.write("Approval Status (Approved, Conditionally Approved, Rejected): \n") f.write("Management Approval (if required):\n") f.write("Date of Approval: \n") f.write("Approving Manager Name: \n") f.write("\n## 13. Supporting Documentation\n") f.write("Attach any relevant supporting documentation, such as:\n") f.write("- Vendor security questionnaires\n") f.write("- Penetration testing reports\n") f.write("- Security audit reports\n") f.write("- Privacy impact assessments\n") def main(): """Collects assessment data from user input and generates documents.""" data = {} # 1. Requestor Information data['requestor_name'] = input("Enter your name: ") data['department'] = input("Enter your department: ") data['email'] = input("Enter your email address: ") data['phone'] = input("Enter your phone number: ") # 2. Request Type print("\nRequest Type:") print("1. New Software/Vendor") print("2. Existing Software/Vendor (Renewal/Upgrade)") print("3. Software/Vendor Decommissioning") choice = input("Enter your choice (1-3): ") request_types = { "1": "New Software/Vendor", "2": "Existing Software/Vendor (Renewal/Upgrade)", "3": "Software/Vendor Decommissioning" } data['request_type'] = request_types.get(choice) # 3. Deployment Model print("\nDeployment Model:") print("1. SaaS (Software as a Service)") print("2. IaaS (Infrastructure as a Service)") print("3. PaaS (Platform as a Service)") print("4. On-Premises (Internally Hosted)") print("5. Hybrid") print("6. Cloud-Hosted") print("7. Other (Please Specify)") choice = input("Enter your choice (1-7): ") if choice == "7": data['deployment_model'] = input("Specify the deployment model: ") else: deployment_models = { "1": "SaaS (Software as a Service)", "2": "IaaS (Infrastructure as a Service)", "3": "PaaS (Platform as a Service)", "4": "On-Premises (Internally Hosted)", "5": "Hybrid", "6": "Cloud-Hosted" } data['deployment_model'] = deployment_models.get(choice) # 4. Software/Vendor Information data['vendor_name'] = input("Enter the Software/Vendor Name: ") data['software_name'] = input("Enter the Software Name: ") data['vendor_website'] = input("Enter the Software/Vendor Website: ") data['vendor_contact'] = input("Enter the Software/Vendor Contact Information: ") data['vendor_description'] = input("Enter a Brief Description of Software/Vendor and its Purpose: ") # 5. Intended Use data['intended_use'] = input("Describe how the software/vendor will be used within the company: ") data['departments_teams'] = input("Specify the departments or teams that will be using the software/vendor: ") data['critical_processes_data'] = input("Identify any critical business processes or data that will be impacted by the software/vendor: ") # 6. Prerequisites data['os_requirements'] = input("List any Operating System Requirements: ") data['hardware_requirements'] = input("List any Hardware Requirements (e.g., RAM, storage space): ") data['network_connectivity'] = input("List any Network Connectivity Requirements (e.g., bandwidth, VPN): ") data['software_dependencies'] = input("List any Software Dependencies (e.g., libraries, frameworks): ") data['user_access_requirements'] = input("List any User Access Requirements (e.g., specific roles, permissions): ") data['other_prerequisites'] = input("List any Other Prerequisites: ") # 7. Technical Information data['hosting_environment'] = input("Provide the Hosting Environment (e.g., cloud provider, on-premise data center): ") data['network_requirements'] = input("Provide the Network Requirements (e.g., ports, protocols, firewall rules): ") data['data_storage_requirements'] = input("Provide the Data Storage Requirements (e.g., location, encryption, data retention policies): ") data['integration_existing_systems'] = input("Describe the Integration with Existing Systems (if any): ") data['api_information'] = input("Provide API Information (if applicable): ") # 8. Security Requirements data['data_protection'] = input("Data Security - How will data be protected in transit and at rest?: ") data['data_privacy_compliance'] = input("Data Security - Does the software/vendor comply with relevant data privacy regulations (e.g., GDPR, CCPA)?: ") data['data_encryption_methods'] = input("Data Security - What data encryption methods are used?: ") data['access_control_management'] = input("Access Control - How will access to the software/vendor be granted and managed?: ") data['multi_factor_authentication'] = input("Access Control - Does the software/vendor support multi-factor authentication?: ") data['user_roles_permissions'] = input("Access Control - What user roles and permissions are available?: ") data['vulnerability_disclosure'] = input("Vulnerability Management - Does the software/vendor have a vulnerability disclosure program?: ") data['security_patch_management'] = input("Vulnerability Management - How are security patches and updates managed?: ") data['security_assessments'] = input("Vulnerability Management - Are regular security assessments and penetration testing conducted?: ") data['industry_security_standards'] = input("Compliance - Does the software/vendor comply with relevant industry security standards (e.g., ISO 27001, SOC 2)?: ") data['third_party_certifications'] = input("Compliance - Are there any third-party security certifications or audits available?: ") data['business_continuity_plans'] = input("Business Continuity and Disaster Recovery - What are the software/vendor's business continuity and disaster recovery plans?: ") data['rto_rpo'] = input("Business Continuity and Disaster Recovery - What are the recovery time objectives (RTOs) and recovery point objectives (RPOs)?: ") # 9. Privacy Requirements data['personal_data_collected'] = input("Data Collection - What personal data will be collected by the software/vendor?: ") data['data_collection_purpose'] = input("Data Collection - What is the purpose of collecting this data?: ") data['data_sharing'] = input("Data Collection - Will data be shared with third parties? If so, with whom and for what purpose?: ") data['data_subject_rights'] = input("Data Subject Rights - How does the software/vendor ensure data subject rights (e.g., access, rectification, erasure)?: ") data['privacy_policy'] = input("Data Subject Rights - Does the software/vendor provide a privacy policy that is readily accessible to users?: ") # 10. Legal and Contractual Requirements data['license_agreement'] = input("Provide the Software License Agreement: ") data['sla'] = input("Provide the Service Level Agreement (SLA): ") data['dpa'] = input("Provide the Data Processing Agreement (DPA): ") data['vendor_security_policies'] = input("Provide the Vendor Security Policies: ") # 11. Risk Assessment data['potential_risks'] = input("Identify any potential security or privacy risks associated with the use of the software/vendor: ") data['risk_mitigation'] = input("Describe the risk mitigation measures that will be implemented: ") # Generate a unique timestamp timestamp = datetime.datetime.now().strftime("%Y%m%d_%H%M%S") # Sanitize vendor/software name for filename vendor_name = data['vendor_name'].replace(" ", "_").replace("/", "-") software_name = data['software_name'].replace(" ", "_").replace("/", "-") # Create and save the Word document with unique filename doc_filename = f"{vendor_name}_{software_name}_assessment_{timestamp}.docx" doc = create_assessment_doc(data) doc.save(doc_filename) print(f"Word document saved as {doc_filename}") # Convert to PDF with unique filename pdf_filename = f"{vendor_name}_{software_name}_assessment_{timestamp}.pdf" convert(doc_filename, pdf_filename) print(f"PDF document saved as {pdf_filename}") # Create Markdown file with unique filename md_filename = f"{vendor_name}_{software_name}_assessment_{timestamp}.md" create_markdown_file(data, md_filename) # Pass filename to function print(f"Markdown file saved as {md_filename}") if __name__ == "__main__": main()