CDP Control ID:35948469 Category: Reuse of Work Products Frequency: Annually Owner: h.noerenberg Parent:#1
Requirement & Guidance
Reuse of Work Products Requirement: A single point of contact for sharing or removing engagement files or information outside of the client team or client environment (outbound work products) must be identified. Requests for information (internal or client) must be routed through the appropriate process. Maintain a log of outbound documents. Documenting Engagement Level Procedures is required Guidance: Client data may not be shared or reused for purposes beyond what is permitted in the contract between Accenture and the client. Identify an Accenture Leader at engagement level who is responsible for document sharing internally and externally. Add the Enterprise ID for the single point of contact in the Engagement Level Procedures and reassign this control to that person. This PoC has to ensure related client personal data has been de-identified and any such work product(s) has been approved prior to sharing/reuse outside of the project environment. Approvals should come from the CAL / AMD, and legal or CM. This person will also be the point of contact for validating and handling requests from within project and client for sharing project documents. This person is also responsible for confirming authorized re-use of third party intellectual property, across client, ecosystem partners, and competitors.
**CDP Control ID:** `35948469`
**Category:** Reuse of Work Products
**Frequency:** Annually
**Owner:** h.noerenberg
**Parent:** #1
## Requirement & Guidance
Reuse of Work Products Requirement: A single point of contact for sharing or removing engagement files or information outside of the client team or client environment (outbound work products) must be identified. Requests for information (internal or client) must be routed through the appropriate process. Maintain a log of outbound documents. Documenting Engagement Level Procedures is required Guidance: Client data may not be shared or reused for purposes beyond what is permitted in the contract between Accenture and the client. Identify an Accenture Leader at engagement level who is responsible for document sharing internally and externally. Add the Enterprise ID for the single point of contact in the Engagement Level Procedures and reassign this control to that person. This PoC has to ensure related client personal data has been de-identified and any such work product(s) has been approved prior to sharing/reuse outside of the project environment. Approvals should come from the CAL / AMD, and legal or CM. This person will also be the point of contact for validating and handling requests from within project and client for sharing project documents. This person is also responsible for confirming authorized re-use of third party intellectual property, across client, ecosystem partners, and competitors.
Outbound-Requests gehen an SPOC → Approval-Entscheidung → Log
Outbound-Log-Template: Datum | Anfragende Person | Dokument | Ziel | Approval
Evidence: Signiertes Prozess-Dokument + Log (auch wenn leer)
Keine Code-Änderung nötig — Prozess-Control.
### CapaKraken Action Plan — 35948469 SPOC for Info Sharing (Outbound)
**Scope:** Single Point of Contact für das Teilen oder Entfernen von Files/Informationen ausserhalb des Client-Teams.
**Aktueller Stand:**
- Keine formale SPOC-Rolle definiert
**Todos:**
- [ ] SPOC benennen (aktuell sinnvoll: h.noerenberg als Owner)
- [ ] Prozess dokumentieren: `docs/outbound-data-spoc.md` (neu)
- Outbound-Requests gehen an SPOC → Approval-Entscheidung → Log
- [ ] Outbound-Log-Template: Datum | Anfragende Person | Dokument | Ziel | Approval
- [ ] Evidence: Signiertes Prozess-Dokument + Log (auch wenn leer)
**Keine Code-Änderung nötig** — Prozess-Control.
EAPPS-Mapping:Prozess Status:🟡PARTIAL / TODO — konkrete Schritte unten
Zusammenfassung
SPOC (Single Point of Contact) für Security-/Compliance-Anfragen ist eine Prozess-Kontrolle.
Aktuelle Evidenz
Im Epic ist h.noerenberg als Owner benannt.
Keine formale SPOC-Dokumentation im Repo.
Offene Aufgaben
SPOC-Rolle + Kontakt offiziell in docs/README.md oder SECURITY.md benennen.
Backup-Kontakt definieren (Vertretung bei Abwesenheit).
Reaktionszeit-Commitment (z. B. 2 Werktage für Compliance-Anfragen).
Ticket bleibt offen bis alle Aufgaben abgehakt sind.
## CapaKraken Compliance-Status
**EAPPS-Mapping:** `Prozess`
**Status:** 🟡 **PARTIAL / TODO** — konkrete Schritte unten
### Zusammenfassung
SPOC (Single Point of Contact) für Security-/Compliance-Anfragen ist eine Prozess-Kontrolle.
### Aktuelle Evidenz
- Im Epic ist `h.noerenberg` als Owner benannt.
- Keine formale SPOC-Dokumentation im Repo.
### Offene Aufgaben
- [ ] SPOC-Rolle + Kontakt offiziell in `docs/README.md` oder `SECURITY.md` benennen.
- [ ] Backup-Kontakt definieren (Vertretung bei Abwesenheit).
- [ ] Reaktionszeit-Commitment (z. B. 2 Werktage für Compliance-Anfragen).
---
*Ticket bleibt offen bis alle Aufgaben abgehakt sind.*
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
CDP Control ID:
35948469Category: Reuse of Work Products
Frequency: Annually
Owner: h.noerenberg
Parent: #1
Requirement & Guidance
Reuse of Work Products Requirement: A single point of contact for sharing or removing engagement files or information outside of the client team or client environment (outbound work products) must be identified. Requests for information (internal or client) must be routed through the appropriate process. Maintain a log of outbound documents. Documenting Engagement Level Procedures is required Guidance: Client data may not be shared or reused for purposes beyond what is permitted in the contract between Accenture and the client. Identify an Accenture Leader at engagement level who is responsible for document sharing internally and externally. Add the Enterprise ID for the single point of contact in the Engagement Level Procedures and reassign this control to that person. This PoC has to ensure related client personal data has been de-identified and any such work product(s) has been approved prior to sharing/reuse outside of the project environment. Approvals should come from the CAL / AMD, and legal or CM. This person will also be the point of contact for validating and handling requests from within project and client for sharing project documents. This person is also responsible for confirming authorized re-use of third party intellectual property, across client, ecosystem partners, and competitors.
CapaKraken Action Plan — 35948469 SPOC for Info Sharing (Outbound)
Scope: Single Point of Contact für das Teilen oder Entfernen von Files/Informationen ausserhalb des Client-Teams.
Aktueller Stand:
Todos:
docs/outbound-data-spoc.md(neu)Keine Code-Änderung nötig — Prozess-Control.
CapaKraken Compliance-Status
EAPPS-Mapping:
ProzessStatus: 🟡 PARTIAL / TODO — konkrete Schritte unten
Zusammenfassung
SPOC (Single Point of Contact) für Security-/Compliance-Anfragen ist eine Prozess-Kontrolle.
Aktuelle Evidenz
h.noerenbergals Owner benannt.Offene Aufgaben
docs/README.mdoderSECURITY.mdbenennen.Ticket bleibt offen bis alle Aufgaben abgehakt sind.
Action Plan
CDP-Requirement: Single Point of Contact für Outbound-Sharing von Projekt-Dokumenten/Daten designieren.
Designation
TODOs
docs/engagement-level-procedures.mdanlegen mit Sektion:docs/evidence/outbound-sharing-log.mdals einfache Tabelle (Date | Artifact | Recipient | Purpose | Approval-Ref).Frequency: Annual Review.
Blocker: Keine — rein organisatorisch.