Files
personal_development/Security Stack/SecurityReview/SoftwareSecurityReview.py
T
2025-08-04 12:58:29 -04:00

340 lines
23 KiB
Python

import datetime
from docx import Document
from docx2pdf import convert
def create_assessment_doc(data):
"""Creates a Word document from the assessment data."""
document = Document()
document.add_heading('Software/Vendor Security Assessment Request', 0)
# 1. Requestor Information
document.add_heading('1. Requestor Information', level=1)
document.add_paragraph(f"Name: {data['requestor_name']}")
document.add_paragraph(f"Department: {data['department']}")
document.add_paragraph(f"Email Address: {data['email']}")
document.add_paragraph(f"Phone Number: {data['phone']}")
# 2. Request Type
document.add_heading('2. Request Type', level=1)
document.add_paragraph(data['request_type'])
# 3. Deployment Model
document.add_heading('3. Deployment Model', level=1)
document.add_paragraph(data['deployment_model'])
# 4. Software/Vendor Information
document.add_heading('4. Software/Vendor Information', level=1)
document.add_paragraph(f"Software/Vendor Name: {data['vendor_name']}")
document.add_paragraph(f"Software Name: {data['software_name']}")
document.add_paragraph(f"Software/Vendor Website: {data['vendor_website']}")
document.add_paragraph(f"Software/Vendor Contact Information: {data['vendor_contact']}")
document.add_paragraph(f"Brief Description of Software/Vendor and its Purpose: {data['vendor_description']}")
# 5. Intended Use
document.add_heading('5. Intended Use', level=1)
document.add_paragraph(f"Describe how the software/vendor will be used within the company: {data['intended_use']}")
document.add_paragraph(f"Specify the departments or teams that will be using the software/vendor: {data['departments_teams']}")
document.add_paragraph(f"Identify any critical business processes or data that will be impacted by the software/vendor: {data['critical_processes_data']}")
# 6. Prerequisites
document.add_heading('6. Prerequisites', level=1)
document.add_paragraph(f"Operating System Requirements: {data['os_requirements']}")
document.add_paragraph(f"Hardware Requirements (e.g., RAM, storage space): {data['hardware_requirements']}")
document.add_paragraph(f"Network Connectivity (e.g., bandwidth, VPN): {data['network_connectivity']}")
document.add_paragraph(f"Software Dependencies (e.g., libraries, frameworks): {data['software_dependencies']}")
document.add_paragraph(f"User Access Requirements (e.g., specific roles, permissions): {data['user_access_requirements']}")
document.add_paragraph(f"Other Prerequisites: {data['other_prerequisites']}")
# 7. Technical Information
document.add_heading('7. Technical Information', level=1)
document.add_paragraph(f"Hosting Environment (e.g., cloud provider, on-premise data center): {data['hosting_environment']}")
document.add_paragraph(f"Network Requirements (e.g., ports, protocols, firewall rules): {data['network_requirements']}")
document.add_paragraph(f"Data Storage Requirements (e.g., location, encryption, data retention policies): {data['data_storage_requirements']}")
document.add_paragraph(f"Integration with Existing Systems (if any): {data['integration_existing_systems']}")
document.add_paragraph(f"API Information (if applicable): {data['api_information']}")
# 8. Security Requirements
document.add_heading('8. Security Requirements', level=1)
document.add_paragraph(f"Data Security - How will data be protected in transit and at rest?: {data['data_protection']}")
document.add_paragraph(f"Data Security - Does the software/vendor comply with relevant data privacy regulations (e.g., GDPR, CCPA)?: {data['data_privacy_compliance']}")
document.add_paragraph(f"Data Security - What data encryption methods are used?: {data['data_encryption_methods']}")
document.add_paragraph(f"Access Control - How will access to the software/vendor be granted and managed?: {data['access_control_management']}")
document.add_paragraph(f"Access Control - Does the software/vendor support multi-factor authentication?: {data['multi_factor_authentication']}")
document.add_paragraph(f"Access Control - What user roles and permissions are available?: {data['user_roles_permissions']}")
document.add_paragraph(f"Vulnerability Management - Does the software/vendor have a vulnerability disclosure program?: {data['vulnerability_disclosure']}")
document.add_paragraph(f"Vulnerability Management - How are security patches and updates managed?: {data['security_patch_management']}")
document.add_paragraph(f"Vulnerability Management - Are regular security assessments and penetration testing conducted?: {data['security_assessments']}")
document.add_paragraph(f"Compliance - Does the software/vendor comply with relevant industry security standards (e.g., ISO 27001, SOC 2)?: {data['industry_security_standards']}")
document.add_paragraph(f"Compliance - Are there any third-party security certifications or audits available?: {data['third_party_certifications']}")
document.add_paragraph(f"Business Continuity and Disaster Recovery - What are the software/vendor's business continuity and disaster recovery plans?: {data['business_continuity_plans']}")
document.add_paragraph(f"Business Continuity and Disaster Recovery - What are the recovery time objectives (RTOs) and recovery point objectives (RPOs)?: {data['rto_rpo']}")
# 9. Privacy Requirements
document.add_heading('9. Privacy Requirements', level=1)
document.add_paragraph(f"Data Collection - What personal data will be collected by the software/vendor?: {data['personal_data_collected']}")
document.add_paragraph(f"Data Collection - What is the purpose of collecting this data?: {data['data_collection_purpose']}")
document.add_paragraph(f"Data Collection - Will data be shared with third parties? If so, with whom and for what purpose?: {data['data_sharing']}")
document.add_paragraph(f"Data Subject Rights - How does the software/vendor ensure data subject rights (e.g., access, rectification, erasure)?: {data['data_subject_rights']}")
document.add_paragraph(f"Data Subject Rights - Does the software/vendor provide a privacy policy that is readily accessible to users?: {data['privacy_policy']}")
# 10. Legal and Contractual Requirements
document.add_heading('10. Legal and Contractual Requirements', level=1)
document.add_paragraph(f"Software License Agreement: {data['license_agreement']}")
document.add_paragraph(f"Service Level Agreement (SLA): {data['sla']}")
document.add_paragraph(f"Data Processing Agreement (DPA): {data['dpa']}")
document.add_paragraph(f"Vendor Security Policies: {data['vendor_security_policies']}")
# 11. Risk Assessment
document.add_heading('11. Risk Assessment', level=1)
document.add_paragraph(f"Identify any potential security or privacy risks associated with the use of the software/vendor: {data['potential_risks']}")
document.add_paragraph(f"Describe the risk mitigation measures that will be implemented: {data['risk_mitigation']}")
# 12. Approval (This section will likely be filled later)
document.add_heading('12. Approval', level=1)
document.add_paragraph("Security Analyst Review:")
document.add_paragraph("Date of Review: ")
document.add_paragraph("Security Analyst Name: ")
document.add_paragraph("Security Assessment Findings: ")
document.add_paragraph("Approval Status (Approved, Conditionally Approved, Rejected): ")
document.add_paragraph("Management Approval (if required):")
document.add_paragraph("Date of Approval: ")
document.add_paragraph("Approving Manager Name: ")
# 13. Supporting Documentation
document.add_heading('13. Supporting Documentation', level=1)
document.add_paragraph("Attach any relevant supporting documentation, such as:")
document.add_paragraph("Vendor security questionnaires")
document.add_paragraph("Penetration testing reports")
document.add_paragraph("Security audit reports")
document.add_paragraph("Privacy impact assessments")
return document
def create_markdown_file(data, md_filename): # Receive filename as argument
"""Creates a Markdown file from the assessment data."""
with open(md_filename, "w") as f: # Use the provided filename
# Add all the headings and data from the form in Markdown format
f.write("# Software/Vendor Security Assessment Request\n\n")
f.write("## 1. Requestor Information\n")
f.write(f"Name: {data['requestor_name']}\n")
f.write(f"Department: {data['department']}\n")
f.write(f"Email Address: {data['email']}\n")
f.write(f"Phone Number: {data['phone']}\n")
f.write("\n## 2. Request Type\n")
f.write(f"{data['request_type']}\n")
f.write("\n## 3. Deployment Model\n")
f.write(f"{data['deployment_model']}\n")
f.write("\n## 4. Software/Vendor Information\n")
f.write(f"Software/Vendor Name: {data['vendor_name']}\n")
f.write(f"Software Name: {data['software_name']}\n")
f.write(f"Software/Vendor Website: {data['vendor_website']}\n")
f.write(f"Software/Vendor Contact Information: {data['vendor_contact']}\n")
f.write(f"Brief Description of Software/Vendor and its Purpose: {data['vendor_description']}\n")
f.write("\n## 5. Intended Use\n")
f.write(f"Describe how the software/vendor will be used within the company: {data['intended_use']}\n")
f.write(f"Specify the departments or teams that will be using the software/vendor: {data['departments_teams']}\n")
f.write(f"Identify any critical business processes or data that will be impacted by the software/vendor: {data['critical_processes_data']}\n")
f.write("\n## 6. Prerequisites\n")
f.write(f"Operating System Requirements: {data['os_requirements']}\n")
f.write(f"Hardware Requirements (e.g., RAM, storage space): {data['hardware_requirements']}\n")
f.write(f"Network Connectivity (e.g., bandwidth, VPN): {data['network_connectivity']}\n")
f.write(f"Software Dependencies (e.g., libraries, frameworks): {data['software_dependencies']}\n")
f.write(f"User Access Requirements (e.g., specific roles, permissions): {data['user_access_requirements']}\n")
f.write(f"Other Prerequisites: {data['other_prerequisites']}\n")
f.write("\n## 7. Technical Information\n")
f.write(f"Hosting Environment (e.g., cloud provider, on-premise data center): {data['hosting_environment']}\n")
f.write(f"Network Requirements (e.g., ports, protocols, firewall rules): {data['network_requirements']}\n")
f.write(f"Data Storage Requirements (e.g., location, encryption, data retention policies): {data['data_storage_requirements']}\n")
f.write(f"Integration with Existing Systems (if any): {data['integration_existing_systems']}\n")
f.write(f"API Information (if applicable): {data['api_information']}\n")
f.write("\n## 8. Security Requirements\n")
f.write(f"Data Security - How will data be protected in transit and at rest?: {data['data_protection']}\n")
f.write(f"Data Security - Does the software/vendor comply with relevant data privacy regulations (e.g., GDPR, CCPA)?: {data['data_privacy_compliance']}\n")
f.write(f"Data Security - What data encryption methods are used?: {data['data_encryption_methods']}\n")
f.write(f"Access Control - How will access to the software/vendor be granted and managed?: {data['access_control_management']}\n")
f.write(f"Access Control - Does the software/vendor support multi-factor authentication?: {data['multi_factor_authentication']}\n")
f.write(f"Access Control - What user roles and permissions are available?: {data['user_roles_permissions']}\n")
f.write(f"Vulnerability Management - Does the software/vendor have a vulnerability disclosure program?: {data['vulnerability_disclosure']}\n")
f.write(f"Vulnerability Management - How are security patches and updates managed?: {data['security_patch_management']}\n")
f.write(f"Vulnerability Management - Are regular security assessments and penetration testing conducted?: {data['security_assessments']}\n")
f.write(f"Compliance - Does the software/vendor comply with relevant industry security standards (e.g., ISO 27001, SOC 2)?: {data['industry_security_standards']}\n")
f.write(f"Compliance - Are there any third-party security certifications or audits available?: {data['third_party_certifications']}\n")
f.write(f"Business Continuity and Disaster Recovery - What are the software/vendor's business continuity and disaster recovery plans?: {data['business_continuity_plans']}\n")
f.write(f"Business Continuity and Disaster Recovery - What are the recovery time objectives (RTOs) and recovery point objectives (RPOs)?: {data['rto_rpo']}\n")
f.write("\n## 9. Privacy Requirements\n")
f.write(f"Data Collection - What personal data will be collected by the software/vendor?: {data['personal_data_collected']}\n")
f.write(f"Data Collection - What is the purpose of collecting this data?: {data['data_collection_purpose']}\n")
f.write(f"Data Collection - Will data be shared with third parties? If so, with whom and for what purpose?: {data['data_sharing']}\n")
f.write(f"Data Subject Rights - How does the software/vendor ensure data subject rights (e.g., access, rectification, erasure)?: {data['data_subject_rights']}\n")
f.write(f"Data Subject Rights - Does the software/vendor provide a privacy policy that is readily accessible to users?: {data['privacy_policy']}\n")
f.write("\n## 10. Legal and Contractual Requirements\n")
f.write(f"Software License Agreement: {data['license_agreement']}\n")
f.write(f"Service Level Agreement (SLA): {data['sla']}\n")
f.write(f"Data Processing Agreement (DPA): {data['dpa']}\n")
f.write(f"Vendor Security Policies: {data['vendor_security_policies']}\n")
f.write("\n## 11. Risk Assessment\n")
f.write(f"Identify any potential security or privacy risks associated with the use of the software/vendor: {data['potential_risks']}\n")
f.write(f"Describe the risk mitigation measures that will be implemented: {data['risk_mitigation']}\n")
f.write("\n## 12. Approval\n")
f.write("Security Analyst Review:\n")
f.write("Date of Review: \n")
f.write("Security Analyst Name: \n")
f.write("Security Assessment Findings: \n")
f.write("Approval Status (Approved, Conditionally Approved, Rejected): \n")
f.write("Management Approval (if required):\n")
f.write("Date of Approval: \n")
f.write("Approving Manager Name: \n")
f.write("\n## 13. Supporting Documentation\n")
f.write("Attach any relevant supporting documentation, such as:\n")
f.write("- Vendor security questionnaires\n")
f.write("- Penetration testing reports\n")
f.write("- Security audit reports\n")
f.write("- Privacy impact assessments\n")
def main():
"""Collects assessment data from user input and generates documents."""
data = {}
# 1. Requestor Information
data['requestor_name'] = input("Enter your name: ")
data['department'] = input("Enter your department: ")
data['email'] = input("Enter your email address: ")
data['phone'] = input("Enter your phone number: ")
# 2. Request Type
print("\nRequest Type:")
print("1. New Software/Vendor")
print("2. Existing Software/Vendor (Renewal/Upgrade)")
print("3. Software/Vendor Decommissioning")
choice = input("Enter your choice (1-3): ")
request_types = {
"1": "New Software/Vendor",
"2": "Existing Software/Vendor (Renewal/Upgrade)",
"3": "Software/Vendor Decommissioning"
}
data['request_type'] = request_types.get(choice)
# 3. Deployment Model
print("\nDeployment Model:")
print("1. SaaS (Software as a Service)")
print("2. IaaS (Infrastructure as a Service)")
print("3. PaaS (Platform as a Service)")
print("4. On-Premises (Internally Hosted)")
print("5. Hybrid")
print("6. Cloud-Hosted")
print("7. Other (Please Specify)")
choice = input("Enter your choice (1-7): ")
if choice == "7":
data['deployment_model'] = input("Specify the deployment model: ")
else:
deployment_models = {
"1": "SaaS (Software as a Service)",
"2": "IaaS (Infrastructure as a Service)",
"3": "PaaS (Platform as a Service)",
"4": "On-Premises (Internally Hosted)",
"5": "Hybrid",
"6": "Cloud-Hosted"
}
data['deployment_model'] = deployment_models.get(choice)
# 4. Software/Vendor Information
data['vendor_name'] = input("Enter the Software/Vendor Name: ")
data['software_name'] = input("Enter the Software Name: ")
data['vendor_website'] = input("Enter the Software/Vendor Website: ")
data['vendor_contact'] = input("Enter the Software/Vendor Contact Information: ")
data['vendor_description'] = input("Enter a Brief Description of Software/Vendor and its Purpose: ")
# 5. Intended Use
data['intended_use'] = input("Describe how the software/vendor will be used within the company: ")
data['departments_teams'] = input("Specify the departments or teams that will be using the software/vendor: ")
data['critical_processes_data'] = input("Identify any critical business processes or data that will be impacted by the software/vendor: ")
# 6. Prerequisites
data['os_requirements'] = input("List any Operating System Requirements: ")
data['hardware_requirements'] = input("List any Hardware Requirements (e.g., RAM, storage space): ")
data['network_connectivity'] = input("List any Network Connectivity Requirements (e.g., bandwidth, VPN): ")
data['software_dependencies'] = input("List any Software Dependencies (e.g., libraries, frameworks): ")
data['user_access_requirements'] = input("List any User Access Requirements (e.g., specific roles, permissions): ")
data['other_prerequisites'] = input("List any Other Prerequisites: ")
# 7. Technical Information
data['hosting_environment'] = input("Provide the Hosting Environment (e.g., cloud provider, on-premise data center): ")
data['network_requirements'] = input("Provide the Network Requirements (e.g., ports, protocols, firewall rules): ")
data['data_storage_requirements'] = input("Provide the Data Storage Requirements (e.g., location, encryption, data retention policies): ")
data['integration_existing_systems'] = input("Describe the Integration with Existing Systems (if any): ")
data['api_information'] = input("Provide API Information (if applicable): ")
# 8. Security Requirements
data['data_protection'] = input("Data Security - How will data be protected in transit and at rest?: ")
data['data_privacy_compliance'] = input("Data Security - Does the software/vendor comply with relevant data privacy regulations (e.g., GDPR, CCPA)?: ")
data['data_encryption_methods'] = input("Data Security - What data encryption methods are used?: ")
data['access_control_management'] = input("Access Control - How will access to the software/vendor be granted and managed?: ")
data['multi_factor_authentication'] = input("Access Control - Does the software/vendor support multi-factor authentication?: ")
data['user_roles_permissions'] = input("Access Control - What user roles and permissions are available?: ")
data['vulnerability_disclosure'] = input("Vulnerability Management - Does the software/vendor have a vulnerability disclosure program?: ")
data['security_patch_management'] = input("Vulnerability Management - How are security patches and updates managed?: ")
data['security_assessments'] = input("Vulnerability Management - Are regular security assessments and penetration testing conducted?: ")
data['industry_security_standards'] = input("Compliance - Does the software/vendor comply with relevant industry security standards (e.g., ISO 27001, SOC 2)?: ")
data['third_party_certifications'] = input("Compliance - Are there any third-party security certifications or audits available?: ")
data['business_continuity_plans'] = input("Business Continuity and Disaster Recovery - What are the software/vendor's business continuity and disaster recovery plans?: ")
data['rto_rpo'] = input("Business Continuity and Disaster Recovery - What are the recovery time objectives (RTOs) and recovery point objectives (RPOs)?: ")
# 9. Privacy Requirements
data['personal_data_collected'] = input("Data Collection - What personal data will be collected by the software/vendor?: ")
data['data_collection_purpose'] = input("Data Collection - What is the purpose of collecting this data?: ")
data['data_sharing'] = input("Data Collection - Will data be shared with third parties? If so, with whom and for what purpose?: ")
data['data_subject_rights'] = input("Data Subject Rights - How does the software/vendor ensure data subject rights (e.g., access, rectification, erasure)?: ")
data['privacy_policy'] = input("Data Subject Rights - Does the software/vendor provide a privacy policy that is readily accessible to users?: ")
# 10. Legal and Contractual Requirements
data['license_agreement'] = input("Provide the Software License Agreement: ")
data['sla'] = input("Provide the Service Level Agreement (SLA): ")
data['dpa'] = input("Provide the Data Processing Agreement (DPA): ")
data['vendor_security_policies'] = input("Provide the Vendor Security Policies: ")
# 11. Risk Assessment
data['potential_risks'] = input("Identify any potential security or privacy risks associated with the use of the software/vendor: ")
data['risk_mitigation'] = input("Describe the risk mitigation measures that will be implemented: ")
# Generate a unique timestamp
timestamp = datetime.datetime.now().strftime("%Y%m%d_%H%M%S")
# Sanitize vendor/software name for filename
vendor_name = data['vendor_name'].replace(" ", "_").replace("/", "-")
software_name = data['software_name'].replace(" ", "_").replace("/", "-")
# Create and save the Word document with unique filename
doc_filename = f"{vendor_name}_{software_name}_assessment_{timestamp}.docx"
doc = create_assessment_doc(data)
doc.save(doc_filename)
print(f"Word document saved as {doc_filename}")
# Convert to PDF with unique filename
pdf_filename = f"{vendor_name}_{software_name}_assessment_{timestamp}.pdf"
convert(doc_filename, pdf_filename)
print(f"PDF document saved as {pdf_filename}")
# Create Markdown file with unique filename
md_filename = f"{vendor_name}_{software_name}_assessment_{timestamp}.md"
create_markdown_file(data, md_filename) # Pass filename to function
print(f"Markdown file saved as {md_filename}")
if __name__ == "__main__":
main()