Skip to content

Weekly Security Review

Frequency: Every Monday | SLA: Complete by Friday EOD

Each weekly GitHub Issue is auto-populated with real compliance data by weekly_review.py before it is assigned for review. The issue contains pre-pulled compliance state, incident counts, Dependabot alert totals, and CrowdStrike detection summaries — reviewers read the issue rather than visiting each dashboard.

Tracked as a GitHub Issue using the Weekly Security Review template.


SystemWhat It Provides
Nightly VerificationCompliance state across all 12 systems — auto-pulled into issue
GCP Cloud MonitoringAlert policies, uptime check status, notification channel health — auto-pulled into issue
CrowdStrikeEndpoint detections, prevention events — summary auto-pulled into issue
Google WorkspaceAdmin audit log, login anomalies, DLP violations — evidence/logs/google-workspace/
1PasswordWatchtower findings, sign-in events — evidence/logs/1password/
GitHubDependabot alert counts, secret scanning alerts — auto-pulled into issue
Backblaze / SupabaseBackup status — evidence-external.yml and evidence-supabase.yml workflow runs

#AreaAction
1Compliance stateRead the auto-populated compliance state in the issue. Open dashboards only for items flagged as FAIL or ERROR.
2Uptime and incidentsReview GCP Cloud Monitoring alert summary in the issue. Investigate any flagged uptime check failures or alert policy firings.
3Dependency vulnerabilitiesReview the Dependabot alert count in the issue. Escalate critical/high findings as vulnerability remediation issues.
4Endpoint protectionReview the CrowdStrike detection summary in the issue. Open falcon.crowdstrike.com only if detections are flagged.
5Workflow healthConfirm all evidence and verify workflows completed successfully. Check #security-alerts for any failures.

Most checklist items are pre-populated in the issue. Add comments for any findings that require follow-up, link remediation issues, then close the review issue. Remediation items are tracked as separate issues.



Meridian Seven — Confidential