cds-snc / platform-forms-client

NextJS application that serves the public-facing website for Forms
https://forms-staging.cdssandbox.xyz/
MIT License
35 stars 13 forks source link

AC-2(3) Disable Inactive Accounts #851

Open srtalbot opened 2 years ago

srtalbot commented 2 years ago

Security Story

Story context From security assessor:

CDS should investigate if an access control feature could be implemented which would automatically disable accounts if they haven’t been used within an organizationally defined period of time.

There are three kinds of accounts we should consider:

Acceptance criteria

srtalbot commented 2 years ago

High effort implementation from a technical and service design perspective.