# Secure Board Portal Checklist: Identity, Authorization, Data, and Incident Response

> Board packs contain MNPI, M&A plans, HR investigations, cyber briefings, and strategy. Attackers phish directors; insiders mis-forward; former directors…

Source: https://preparedboard.com/guides/secure-board-portal-checklist · Updated 2026-10-07

**Target keyword:** secure board portal  
**Intent:** Informational / Checklist  
**Last updated:** 2026-10-07  

---

## Boards are high-value targets — portals must assume breach and insider risk

Board packs contain MNPI, M&A plans, HR investigations, cyber briefings, and strategy. Attackers phish directors; insiders mis-forward; former directors retain access; misconfigured permissions expose “board” rooms to the wrong roles. A secure board portal is not only TLS and a certification badge — it is **identity, authorization, data protection, logging, and incident response** practiced operationally.

This checklist is for CISOs, GCs, corporate secretaries, and procurement evaluating or operating a portal — including Diligent-class suites and modern mid-market tools.

---

## 1) Identity & authentication

- [ ] SSO via SAML/OIDC to corporate IdP (Okta/Azure AD/Google) for employees/admins  
- [ ] Strong MFA enforced (phishing-resistant where possible: passkeys/WebAuthn)  
- [ ] Director-friendly auth options that do not push them to shared passwords (magic link + MFA, passkeys)  
- [ ] No shared generic “board@” logins  
- [ ] Session timeouts appropriate for MNPI  
- [ ] Device posture considerations for high-sensitivity boards  
- [ ] Prompt offboarding within hours of resignation/removal  

**Test:** Remove a director account and confirm web + mobile access dies within your SLA (aim: minutes).

---

## 2) Authorization (the industry soft spot)

Authorization failures have driven real-world board-tool incidents. Checklist:

- [ ] Least-privilege roles: admin, secretary, director, observer, auditor, guest presenter  
- [ ] Separate permissions for full board vs. committees vs. executive session materials  
- [ ] Observers excluded from executive session by default  
- [ ] Object-level ACL on folders/meetings/decisions — not only site membership  
- [ ] Prevent link enumeration / guessable public URLs for packs  
- [ ] Admin actions dual-controlled or heavily logged  
- [ ] Regular access reviews (quarterly) signed by Corporate Secretary  
- [ ] Vendor support access visible and time-bounded  

**Test:** Attempt to access executive-session minutes as an observer and as a recently removed user. Attempt IDOR-style access to another board’s meeting ID if multi-tenant.

---

## 3) Data protection

- [ ] Encryption in transit (TLS 1.2+) and at rest  
- [ ] Watermarking on view/download (user, time, IP)  
- [ ] Remote revoke / remote wipe for offline mobile caches  
- [ ] Optional customer-managed keys for higher-sensitivity tenants  
- [ ] Data residency controls if required; understand if region is locked at signup  
- [ ] DLP: restrict bulk download where appropriate  
- [ ] Clear rules on local download vs. portal streaming  
- [ ] AI features: no training on customer content by default; vault exclusions  

---

## 4) Logging, monitoring, and audit evidence

- [ ] Immutable or tamper-evident audit logs: login, view, download, permission change, export  
- [ ] Logs exportable to customer SIEM  
- [ ] Alerts on anomalous bulk download or permission escalation  
- [ ] Retention of logs aligned to policy (often 1 year+)  
- [ ] Break-glass admin procedures documented  

Audit committees should see a sample log during vendor diligence.

---

## 5) Secure configuration & SDLC (vendor)

Ask for:

- [ ] Current independent security audit report  
- [ ] ISO 27001 (and related) if claimed  
- [ ] Penetration test summary under NDA (annual)  
- [ ] Vulnerability disclosure / bug bounty posture  
- [ ] Secure SDLC and dependency scanning  
- [ ] Subprocessor list and change notification  
- [ ] Background on multi-tenant isolation design  
- [ ] Status page and incident history honesty  

Badges without answers on authorization testing are insufficient post-industry misconfiguration incidents.

---

## 6) Operational security (your side)

- [ ] Portal-only distribution policy for board packs (no email attachments)  
- [ ] Director device guidance (disk encryption, auto-lock)  
- [ ] Prohibition on forwarding magic links  
- [ ] Executive-session admission rehearsed  
- [ ] Legal hold capability tested  
- [ ] Offboarding checklist tied to HR/board resignations  
- [ ] Phishing simulations that include fake “board pack” lures  

---

## 7) Incident response

- [ ] Joint IR contacts with vendor (24/7 path)  
- [ ] Breach notification contractual timelines  
- [ ] Playbook: stolen director laptop with offline packs  
- [ ] Playbook: mis-shared link to observers  
- [ ] Playbook: former director still receiving calendar invites  
- [ ] Comms templates for board notification without panic  
- [ ] Forensic log preservation steps  

Tabletop once a year with Secretary + CISO + GC.

---

## 8) Privacy & privilege

- [ ] Minimize PII in packs; separate HR annexes  
- [ ] Understand privilege risks of director employer email — keep sensitive discussion in-portal  
- [ ] DPA signed; SCCs if cross-border  
- [ ] Retention schedule enforced (minutes permanent; recordings short)  

---

## Scoring sheet (quick)

Give 0–2 points per checklist section (max 16). Below 10: do not put MNPI in the tool until gaps close. 10–13: acceptable with compensating controls. 14–16: strong operating posture.

---

## Segment nuances

**Startups:** magic-link convenience must still pair with revoke and watermark.  
**Nonprofits:** volunteer directors on personal devices — invest in training and revoke drills.  
**Public cos / PE:** SSO/SCIM and SIEM export become mandatory procurement items.  
**Credit unions / healthcare-adjacent:** expect deeper questionnaires, BAA if applicable, residency.

---

## Procurement questions that matter

1. Show a permission model diagram for board / committee / exec session / observer.  
2. Demonstrate disable-user on iOS offline pack.  
3. Provide last pen-test executive summary.  
4. Confirm AI training policy in writing.  
5. Provide sample audit log export.  
6. State residency and key management options.  
7. Describe support access to customer tenants.  

---

## Identity deep dive: directors are not employees

Employee SSO is easy; outside directors often use personal emails. Options:

1. Invite them as guests in your IdP (works; governance overhead).  
2. Portal-native passkey / magic-link with MFA and strong revoke.  
3. Separate board IdP tenant (rare; heavy).  

Whatever you choose, **identity proofing** at first enrollment matters — verify the human is the director, not an assistant using a forwarded invite. Assistants may need their own lower-privilege accounts, never shared credentials.

---

## Authorization scenarios to script in RFPs

1. Director on Audit only cannot open Comp committee folder.  
2. Observer cannot open executive session annex.  
3. Presenter link expires after the meeting window.  
4. Former director loses offline mobile access.  
5. Vendor support cannot read packs without explicit customer approval event.  
6. Multi-board admin at a PE firm cannot browse unrelated portco rooms.

If the vendor demos only “admin vs user,” keep pressing.

---

## Data classification inside the portal

Label materials: Public board book / Confidential / Restricted-Exec / Privileged. Map labels to watermark, download, and ACL defaults. Not every slide deck deserves the same controls as a whistleblower investigation annex. Classification prevents both under-protection and unusable lockdown that drives directors back to email.

---

## Third-party risk: integrations

Calendar sync, e-sign, AI summarizers, and SIEM connectors expand the blast radius. Review each integration’s scopes, data flows, and kill switches. Disable unused integrations. Prefer vendors that allow per-tenant integration allowlists.

---

## Compliance mapping (illustrative)

| Control theme | Portal evidence |
|---|---|
| Access control | RBAC config export; quarterly review sign-off |
| Auditability | Log samples; SIEM feed |
| Encryption | Trust center; TLS config |
| Incident response | IR plan joint with vendor |
| Vendor risk | independent security audit; pen-test; DPA |

Use this mapping in customer security questionnaires when your board tool is in scope.

---

## Building a board-specific threat model (short)

Threats: phished director credentials; malicious insider observer; misconfigured public link; lost unlocked tablet; vendor support overreach; AI tool exfiltrating pack text; ransomware on admin laptop with exports; divorced-spouse access to home computer; journalist receiving forwarded PDF.

Controls map: MFA/passkeys; least privilege; no public links; wipe/watermark; time-bounded support; AI no-train + disable; encrypted exports; disk encryption guidance; DLP culture.

Write the threat model on one page and attach it to the procurement file — it focuses debates better than feature bingo.

---

## Executive session security checklist

- [ ] Separate meeting object or folder with stricter ACL  
- [ ] Management and observers removed from video and portal simultaneously  
- [ ] Minutes stored separately with restricted roles  
- [ ] No AI notetaker admitted  
- [ ] Print/download disabled if policy requires  
- [ ] Attendance logged  

Executive session is where portals most often fail operationally.

---

## Mobile offline packs

Offline access helps airplanes and weak hotel Wi-Fi — and increases loss risk. Require:

- Encrypted container on device  
- Remote wipe/revoke  
- Timeout on offline cache  
- Watermarking still applied  
- Policy on downloading to personal file apps (usually forbid)

Demo revoke with offline mode enabled during procurement.

---

## Metrics for the CISO / Audit joint review

- Time to revoke access (median)  
- % directors with MFA  
- Stale accounts >30 days after role end  
- Bulk download events reviewed  
- Open portal vulnerabilities from pen-test  
- Training completion for directors  

Put two of these on the audit committee dashboard annually.

---

## FAQ

**Is an independent audit report enough?** Necessary, not sufficient — test authorization and revoke.  
**Should we record meetings for security?** Usually no; recordings expand breach and discovery surface. Prefer minutes.  
**Are passkeys ready for directors?** Increasingly yes; offer fallback MFA.  
**Who owns portal security — IT or the secretary?** Shared: IT/CISO owns control design; secretary owns access hygiene and operating cadence.  
**What is the first control to implement this week?** Offboard stale users and enforce MFA — high impact, low drama.

---

## Closing operating rule

If you cannot revoke a director’s access quickly, prove who viewed a pack, and export logs for counsel, you do not yet have a secure board portal — regardless of marketing badges. Fix identity, authorization, and evidence first; then optimize UX.

---



---



---


## Sample annual attestation (Corporate Secretary + CISO)

“We attest that: (1) MFA is enforced for all portal users; (2) access reviews for board/committee/observer roles were completed on [date]; (3) disable-user tested on web and mobile on [date] with result [minutes]; (4) no known public links to restricted packs; (5) vendor security audit report reviewed; (6) IR contacts current.”

File with audit committee materials.

---

## Prefer portal streaming over unmanaged downloads

Where feasible, default directors to in-browser viewing with watermarking, and allow downloads only for roles that need them. Every unmanaged PDF is a future forward. Balance usability: total lockdown drives shadow IT — pair restrictions with excellent mobile viewing.

---

## How this maps to Prepared today

Hold Prepared to the same checklist. Here is what it does today, and where it falls short.

- **Authorization:** confidentiality levels BOARD / EXEC_SESSION / COUNSEL, plus DocumentAcl grants by membership, role, director, or compartment. Observer and guest seats have executive-session, counsel, ungranted, and their own recused items withheld on the server, not just hidden in the page. A recused director is removed from that vote but is not walled off from its material; use confidentiality or grants for that.
- **Revoke:** offboarding a member bumps their `sessionVersion`, which ends their sessions on every device. Pack magic links can be revoked or expire, and a revoked or expired link returns 404, including its `/agent` view.
- **Watermarking:** the document viewer overlays board name, viewer email, and a timestamp on screen. It does not include IP address. Document ACL grants carry a download flag, but Prepared does not serve file downloads today, so there is no download watermark and no offline mobile cache to wipe.
- **Audit export:** the activity log records who did what and when, including `document.viewed`. It exports from the Trust Center and as `activity_log` in the full-record export, with metadata allowlisted so share-link tokens and token hashes are never included. Document files themselves are listed as metadata only.
- **AI:** there is no training pipeline in the codebase, and the AI-use policy says no training on customer content. Briefs and draft minutes are composed from the board's own records, not a foundation model.

What is not live yet: there has been no independent security audit and there is no certification. Sign-in is password-based; MFA is an onboarding checklist row, not an enforced MFA product. SAML/OIDC SSO is built but not live until production credentials are connected, and passkeys are not live. Encryption at rest is planned as provider-managed server-side encryption once hosting is selected, and customer-managed keys (BYOK) are not live. Ask every vendor on your shortlist for the same kind of plain list, and check it against their trust center.

---

## Internal links

- [Board Portal Comparison](https://preparedboard.com/guides/board-portal-comparison)  
- [Board Portal Pricing](https://preparedboard.com/guides/board-portal-pricing)  
- [Diligent Boards Alternatives](https://preparedboard.com/guides/diligent-boards-alternatives)  
- [Migrating Off Diligent Checklist](https://preparedboard.com/guides/migrating-off-diligent-checklist)  
- [Board Pack Best Practices](https://preparedboard.com/guides/board-pack-best-practices)  
- [Board Minutes Retention Schedules](https://preparedboard.com/guides/board-minutes-retention-schedules)  

---

## Conclusion

Secure board portals combine strong identity, ruthless authorization hygiene, data protections that survive lost devices, exportable logs, and rehearsed incident response. Use this checklist in RFPs and in annual access reviews — because board confidentiality is a Care duty, not an IT preference.

---

### Sources

1. Vendor trust center themes (independent security audit, ISO, watermark, wipe claims) — verify per vendor  
2. Industry lessons from public-sector board portal misconfiguration reporting (authorization emphasis)  
3. NACD / cyber oversight themes for boards  
4. Prepared Board security implementation principles  


---

## Monthly operating cadence (secretary + IT)

**Weekly:** offboard any director/observer changes.  
**Monthly:** review admin role list; spot-check executive-session ACLs.  
**Quarterly:** full access review; export log sample; phishing reminder.  
**Annually:** pen-test review with vendor; IR tabletop; retention & hold drill; re-score this checklist.

---

## Red team ideas (authorized testing only)

On a staging board or under written authorization: create an observer; try to open exec session; try meeting IDOR across boards; download as watermarked user and attempt to strip; revoke and confirm offline cache. Never test production destructive paths without CISO approval.

---

## Director one-page hygiene card

Use unique auth; never forward links; don’t photo screens into WhatsApp; report lost devices same day; join virtual meetings from private spaces; complete security reminders annually. Confidentiality is part of loyalty.

---

_Practice guidance, not legal advice. Bylaws, statutes, and counsel control._

Cite this page: Prepared Board, "Secure Board Portal Checklist: Identity, Authorization, Data, and Incident Response," https://preparedboard.com/guides/secure-board-portal-checklist (updated 2026-10-07). Anchor: https://preparedboard.com/guides/secure-board-portal-checklist#cite-this

Product claims are verified at https://preparedboard.com/facts and https://preparedboard.com/agent-facts.json. Anything not listed there is not a Prepared Board claim.
