department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
282 stars 201 forks source link

2024 Q3 Security Review June-Sept 2024: Atlas #83686

Closed jennb33 closed 2 months ago

jennb33 commented 4 months ago

Issue Description

OCTO-DE teams are responsible for periodically reviewing access to systems and applications they manage to ensure that only authorized personnel have the required access and permissions.

OCTO-DE teams periodically review user access to ensure that access is limited to users who currently need to access the systems and applications and that those users have the appropriate permissions.

Platform Security initiates each review cycle and application owners are responsible for executing the process for each application that they own. Once complete, application owners document the results of the access review and send the artifacts to Platform Security to document in eMASS as evidence.

Tasks

Success Metrics

Acceptance Criteria

Timeline

Week of June 3, 2024


Validation

Assignee to add steps to this section. List the actions that need to be taken to confirm this issue is complete. Include any necessary links or context. State the expected outcome.

jennb33 commented 3 months ago

Reach out to @kell-y or @kenmayo with questions or issues

jennb33 commented 2 months ago

7/22 update: @rjohnson2011 reports that work is going smoothly and that this work should be complete by COB 7/23.

rjohnson2011 commented 2 months ago

Atlas Access Review published in the Access Reviews folder -> https://vfs.atlassian.net/wiki/spaces/PSEC/pages/3311829048/Atlas+Access+Review

jennb33 commented 2 months ago

7/24 update: There is a document ready for review, @LindseySaari will review it today!