Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Platform Security Q4 Access Review - Datadog [DUE December 16 2024] #97701

Open
6 tasks
kell-y opened this issue Nov 22, 2024 · 0 comments
Open
6 tasks

Platform Security Q4 Access Review - Datadog [DUE December 16 2024] #97701

kell-y opened this issue Nov 22, 2024 · 0 comments
Labels
platform-security PSEC team issues. Platform-Support-Sprint-Work Tier 1 Support Team Projects, Tasks, Research platform-tech-team-support for Platform Tech Support Matrix Team

Comments

@kell-y
Copy link

kell-y commented Nov 22, 2024

Access Review Description:

OCTO-DE teams are responsible for periodically reviewing access to systems and applications they manage to ensure that only authorized personnel have the required access and permissions.

OCTO-DE teams periodically review user access to ensure that access is limited to users who currently need to access the systems and applications and that those users have the appropriate permissions.

Platform Security initiates each review cycle and application owners are responsible for executing the process for each application that they own. Once complete, application owners document the results of the access review and send the artifacts to Platform Security to document in eMASS as evidence.

Tasks:

The Q4 access reviews should track any users that were removed or changed outside of normal offboarding processes since the last access review completed in September 2024.

Note: For Datadog, we are only analyzing elevated privileges (read access or standard roles only)

  • Remove any users that should no longer have access to the systems or applications. Results must include a list of user access that was changed and why.
  • Cross reference an individual in DataDog that has the read access and cross referencing with request in support role
  • Ensure that existing users have the correct permissions.
  • Ensure that every system has at least two administrators, and that any system which is expected to persist even if administration transitions to a new contractor has at least one administrator who is a government employee.
  • Document the results of the review using the linked template: Datadog.

AC:

  • Notify Platform Security that the access reviews are complete.

Resources:
Below are three links that describe the access review process:

@kell-y kell-y added Platform-Support-Sprint-Work Tier 1 Support Team Projects, Tasks, Research platform-tech-team-support for Platform Tech Support Matrix Team labels Nov 22, 2024
@kell-y kell-y changed the title Copy of Platform Security Access Review - Datadog [DUE September 16 2024] Platform Security Q4 Access Review - Datadog [DUE December 16 2024] Nov 22, 2024
@kell-y kell-y added the platform-security PSEC team issues. label Nov 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
platform-security PSEC team issues. Platform-Support-Sprint-Work Tier 1 Support Team Projects, Tasks, Research platform-tech-team-support for Platform Tech Support Matrix Team
Projects
None yet
Development

No branches or pull requests

2 participants