Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .markdownlint.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,11 @@
"TagProvider",
"TagFilter",
"ContributeFooter",
"Contributors"
"Contributors",
"CertifiedProtocols",
"CertList",
"CertifiedProtocolsWrapper",
"MermaidRenderer"
]
},
"MD037": false,
Expand Down
48 changes: 26 additions & 22 deletions docs/pages/certs/certification-guidelines.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,13 @@ import { TagList, AttributionList, TagProvider, TagFilter, ContributeFooter } fr
<TagList tags={frontmatter.tags} />
<AttributionList contributors={frontmatter.contributors} />

This document provides guidelines for completing security certification questionnaires. It covers how to score individual control questions and when to pursue certification through self-assessment or third-party review.
This document provides guidelines for completing security certification questionnaires. It covers how to score
individual control questions and when to pursue certification through self-assessment or third-party review.

## Self-Assessment

The self-assessment option is suitable for organizations wishing to internally validate their security posture. Self-assessment does not grant official certification, but rather serves as an internal checkpoint.
The self-assessment option is suitable for organizations wishing to internally validate their security posture.
Self-assessment does not grant official certification, but rather serves as an internal checkpoint.

### Scoring Individual Questions

Expand All @@ -30,42 +32,44 @@ The self-assessment option is suitable for organizations wishing to internally v

While not required for self-assessment, we recommend maintaining documentation for each "Yes" response:

- Procedure documents
- Operational records
- Test results
- System configurations
* Procedure documents
* Operational records
* Test results
* System configurations

This documentation can be useful for future audits or third-party reviews, and can help track your own security posture over time.
This documentation can be useful for future audits or third-party reviews, and can help track your own security posture
over time.

## Third-Party Review

Third-party reviews are recommended for organizations seeking formal certification, and involves an external SEAL-certified assessor evaluating your security posture.
Third-party reviews are recommended for organizations seeking formal certification, and involves an external
SEAL-certified assessor evaluating your security posture.

### Scoring Individual Questions

- Implemented: Fully operational with verified evidence
- Partially Implemented: Incomplete or lacks sufficient evidence
- Not Implemented: Control absent
- N/A: Not applicable (provide justification)
* Implemented: Fully operational with verified evidence
* Partially Implemented: Incomplete or lacks sufficient evidence
* Not Implemented: Control absent
* N/A: Not applicable (provide justification)

### Required Evidence Per Control

For each control scored "Implemented," provide:

- Procedure documentation: Policies, versions, approval dates
- Operational proof: Logs, records, tickets showing active use
- Testing/validation: Drill results, incident reports, test outcomes
- Ownership details: Responsible party, review frequency, last update
- Technical artifacts: Configurations, screenshots, system exports
* Procedure documentation: Policies, versions, approval dates
* Operational proof: Logs, records, tickets showing active use
* Testing/validation: Drill results, incident reports, test outcomes
* Ownership details: Responsible party, review frequency, last update
* Technical artifacts: Configurations, screenshots, system exports

### Certification Criteria

Third-party reviewers will issue certification when:

- All critical controls are "Implemented" or "N/A" with justification
- Evidence substantiates all claims
- "Partially Implemented" controls have documented remediation plans
- Overall security posture meets framework requirements
* All critical controls are "Implemented" or "N/A" with justification
* Evidence substantiates all claims
* "Partially Implemented" controls have documented remediation plans
* Overall security posture meets framework requirements

### Review Process

Expand All @@ -74,4 +78,4 @@ Third-party reviewers will issue certification when:
3. Address any findings or requests for additional documentation
4. Receive certification report with findings and recommendations

</TagProvider>
</TagProvider>
7 changes: 5 additions & 2 deletions docs/pages/certs/certified-partners.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,8 @@ import { TagList, AttributionList, TagProvider, TagFilter, ContributeFooter, Cer

## Current Status: Request for Qualifications (RFQ)

SEAL Certifications is currently in the process of establishing our certified auditor partner program. We are actively seeking qualified auditing firms to become authorized certification issuers.
SEAL Certifications is currently in the process of establishing our certified auditor partner program. We are actively
seeking qualified auditing firms to become authorized certification issuers.

### Timeline

Expand All @@ -28,7 +29,9 @@ SEAL Certifications is currently in the process of establishing our certified au

## Becoming a Certified Auditor

SEAL will work with a select group of third-party auditing firms to provide certification audits. SEAL-certified auditors will demonstrate expertise in blockchain security and operational security practices, and will be authorized to conduct audits against the SEAL Certification Framework and issue on-chain attestations.
SEAL will work with a select group of third-party auditing firms to provide certification audits. SEAL-certified
auditors will demonstrate expertise in blockchain security and operational security practices, and will be authorized to
conduct audits against the SEAL Certification Framework and issue on-chain attestations.

If your firm is interested, please fill [out this form](https://securityalliance.typeform.com/CertsAuditor)

Expand Down
6 changes: 4 additions & 2 deletions docs/pages/certs/certified-protocols.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,10 @@ import { TagList, AttributionList, TagProvider, TagFilter, ContributeFooter, Cer
<TagList tags={frontmatter.tags} />
<AttributionList contributors={frontmatter.contributors} />

The following protocols have successfully completed SEAL certifications and received on-chain attestations via the Ethereum Attestation Service (EAS). For more details on each certification, click on the respective badges or view the relevant SFC document.
The following protocols have successfully completed SEAL certifications and received on-chain attestations via the
Ethereum Attestation Service (EAS). For more details on each certification, click on the respective badges or view the
relevant SFC document.

<CertifiedProtocolsWrapper protocolInfo={frontmatter.protocols} />

</TagProvider>
</TagProvider>
14 changes: 9 additions & 5 deletions docs/pages/certs/contributions.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -15,12 +15,16 @@ import { TagList, AttributionList, TagProvider, TagFilter, ContributeFooter } fr
<TagList tags={frontmatter.tags} />
<AttributionList contributors={frontmatter.contributors} />

Like the rest of Frameworks, SEAL Certifications are open-source and accept contributions from the community. However, due to the nature of Certifications, contributions are subject to more stringent review and approval processes managed by Isaac, the initiative lead, and the other Certifications maintainers.
Like the rest of Frameworks, SEAL Certifications are open-source and accept contributions from the community. However,
due to the nature of Certifications, contributions are subject to more stringent review and approval processes managed
by Isaac, the initiative lead, and the other Certifications maintainers.

- If you have suggestions for improving existing Certifications, or ideas for a new Certification, please open an issue in the frameworks repo with the `certifications` tag. We're welcome to feedback and ideas from the community!
- If you're a protocol interested in having your project certified, you can reach out to us through our [protocol interest form](https://securityalliance.typeform.com/CertsWaitlist).
- If you're a security firm interested in becoming a SEAL-approved auditor, please reach out through our [interest form](https://securityalliance.typeform.com/CertsAuditor).
- If you have suggestions for improving existing Certifications, or ideas for a new Certification, please open an issue
in the frameworks repo with the `certifications` tag. We're welcome to feedback and ideas from the community!
- If you're a protocol interested in having your project certified, you can reach out to us through our [protocol
interest form](https://securityalliance.typeform.com/CertsWaitlist).
- If you're a security firm interested in becoming a SEAL-approved auditor, please reach out through our [interest form](https://securityalliance.typeform.com/CertsAuditor).

For more information on contributing to SEAL Certifications, or the rest of Frameworks, please see the [Contributing Guide](/contribute/contributing).

</TagProvider>
</TagProvider>
Loading