Skip to content

simonsMOJ/security-guidance

 
 

Repository files navigation

Security guidance

Overview

This repository contains best-practice guidance and - where appropriate - policy for Ministry of Justice (MOJ) technology security.

The information ranges from formal content such as 'you must'-style documents, through to more informal help and suggestions, such as checklists.

The content is used to help build and operate products at the MOJ.

The work is performed in the open by intent and for compliance with principle. There is no specific aim or expectation of re-use of these materials outside of MOJ purposes - but people are welcome to do so if they wish in accordance with the published license.

Note: As a vibrant, dynamic, work-in progress, this the material should not necessarily be treated as formal, finished, definitive, accurate, etc.

Repository details

This repo is inspired by, and borrows from, GDS's technical guidance site and MOJ's technical guidance.

Content in the master branch is built using Jekyll, and hosted using GitHub Pages. It incorporates HTML, SCSS, JavaScript, and images from GDS's Tech Docs Template, and reworks them to work with Jekyll instead of Middleman.

All commits must be signed.

Information about contributing is provided here.

Getting started

To preview the site locally, we need to use the terminal.

Install Ruby and Bundler, preferably with a Ruby version manager.

Once you have Ruby and Bundler set up, you can install this project's dependencies by running the following in this directory:

bundle install

Making changes

To make changes, edit the appropriate Markdown files in this project. Jekyll (and therefore this site) uses kramdown for its Markdown processing.

Make sure to make changes in a branch, and issue a pull request when you want them to be reviewed and published.

Previewing

We can preview our changes locally by running this command:

bundle exec jekyll serve --watch

This will create a local web server, probably at http://127.0.0.1:4000 (look for the Server address: line). This is only accessible on our own computer, and won't be accessible to anyone else. It's also set up to automatically update (thanks to --watch) when we make changes to the working Markdown files.

Publishing changes

Because we're using GitHub Pages, any changes merged into the master branch will be published automatically. Every change should be reviewed in a pull request, no matter how minor, and we've enabled branch protection to enforce this.

About

Security guidance from the MOJ Digital & Technology Cybersecurity team

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • CSS 95.8%
  • JavaScript 1.7%
  • HTML 1.3%
  • Ruby 1.2%