Spree Commerce Security & Compliance
Security & Compliance
Baseline Controls
- Record password policies, MFA requirements, and session settings enforced in Spree Commerce.
- Note available security modules (WAF, bot protection, backups) and whether they are enabled.
- Track vendor security documentation or certifications.
Privacy & Legal
- Document data retention, cookie consent, and regional compliance settings.
- Capture DPIAs or assessments linked to Spree Commerce deployments.
- Maintain contact info for legal or privacy stakeholders overseeing the platform.
Incident Readiness
- Outline how to snapshot content, databases, or configurations during incidents.
- Store templates for breach notifications or public status updates.
- Schedule tabletop reviews or drills that include Spree Commerce owners.