department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
284 stars 206 forks source link

Platform Security Q4 Access Review - TestRail [DUE December 16 2024] #97704

Open kell-y opened 6 days ago

kell-y commented 6 days ago

Access Review Description:

OCTO-DE teams are responsible for periodically reviewing access to systems and applications they manage to ensure that only authorized personnel have the required access and permissions.

OCTO-DE teams periodically review user access to ensure that access is limited to users who currently need to access the systems and applications and that those users have the appropriate permissions.

Platform Security initiates each review cycle and application owners are responsible for executing the process for each application that they own. Once complete, application owners document the results of the access review and send the artifacts to Platform Security to document in eMASS as evidence.

Tasks:

The Q4 access reviews should track any users that were removed or changed outside of normal offboarding processes since the last access review completed in September 2024.

AC:

Resources: Below are three links that describe the access review process: