<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security_policy_au on The GitLab Handbook</title>
    <link>https://handbook.gitlab.com/tags/security_policy_au/</link>
    <description>Recent content in Security_policy_au on The GitLab Handbook</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <atom:link href="https://handbook.gitlab.com/tags/security_policy_au/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>GitLab Audit Logging Policy</title>
      <link>https://handbook.gitlab.com/handbook/security/security-and-technology-policies/audit-logging-policy/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://handbook.gitlab.com/handbook/security/security-and-technology-policies/audit-logging-policy/</guid>
      <description>&lt;span&#xA;  class=&#34;gl-label gl-label-text-light&#34;&#xA;  style=&#34;&#xA;    --label-background-color: #E24329;&#xA;    --label-inset-border: inset 0 0 0 2px #E24329;&#xA;  &#34;&#xA;&gt;&#xA;  &lt;span class=&#34;gl-link gl-label-link&#34;&gt;&#xA;    &lt;span class=&#34;gl-label-text&#34;&gt; Visibility: Audit &lt;/span&gt;&#xA;  &lt;/span&gt;&#xA;&lt;/span&gt;&#xA;&#xA;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;To ensure the proper operation and security of GitLab.com, GitLab logs critical information system activity.&lt;/p&gt;&#xA;&lt;h2 id=&#34;scope&#34;&gt;Scope&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#scope&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;The audit logging policy applies to all systems within our production environment. The production environment includes all endpoints and cloud assets used in hosting GitLab.com and its subdomains. This may include third-party systems that support the business of GitLab.com.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitLab Teleport Access Policy</title>
      <link>https://handbook.gitlab.com/handbook/engineering/gitlab-com/policies/teleport/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://handbook.gitlab.com/handbook/engineering/gitlab-com/policies/teleport/</guid>
      <description>&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;To ensure an audited access to our terminal/CLI tools like &lt;a href=&#34;https://gitlab.com/gitlab-com/runbooks/-/blob/master/docs/teleport/Connect_to_Database_Console_via_Teleport.md&#34;&gt;Database Access&lt;/a&gt; and &lt;a href=&#34;https://gitlab.com/gitlab-com/runbooks/-/blob/master/docs/teleport/Connect_to_Rails_Console_via_Teleport.md&#34;&gt;Rails Console&lt;/a&gt;, GitLab uses Teleport.&lt;/p&gt;&#xA;&lt;h2 id=&#34;scope&#34;&gt;Scope&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#scope&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;The Teleport Access policy applies to all systems within our production environment that require a terminal or CLI access.&lt;/p&gt;&#xA;&lt;h2 id=&#34;roles--responsibilities&#34;&gt;Roles &amp;amp; Responsibilities&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#roles--responsibilities&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Role&lt;/th&gt;&#xA;          &lt;th&gt;Responsibility&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;GitLab Team Members&lt;/td&gt;&#xA;          &lt;td&gt;Responsible for following the requirements in this policy&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;System Owners&lt;/td&gt;&#xA;          &lt;td&gt;Alignment to this policy&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Code Owners&lt;/td&gt;&#xA;          &lt;td&gt;Responsible for approving changes and exceptions to this policy&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;h2 id=&#34;procedure&#34;&gt;Procedure&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#procedure&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Teleport access is managed through &lt;a href=&#34;https://handbook.gitlab.com/handbook/security/corporate/end-user-services/okta/&#34;&gt;Okta&lt;/a&gt; and is provided as part of a role&amp;rsquo;s baseline group assignment or through an &lt;a href=&#34;https://handbook.gitlab.com/handbook/security/corporate/services/access-requests/&#34;&gt;access request&lt;/a&gt; with appropriate approval&lt;/li&gt;&#xA;&lt;li&gt;Access reviews are performed on a quarterly basis to ensure that all users are appropriate and have appropriate access levels.&lt;/li&gt;&#xA;&lt;li&gt;Teleport Audit Logs must be retained for a defined period of 1 year&lt;/li&gt;&#xA;&lt;li&gt;Teleport Audit Logs must not be modified and or deleted before the defined time of 1 year&lt;/li&gt;&#xA;&lt;li&gt;Access to Teleport Audit log data must be limited based on the principle of least privilege&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;exceptions&#34;&gt;Exceptions&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#exceptions&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Exceptions to this policy will be tracked as per the &lt;a href=&#34;https://handbook.gitlab.com/handbook/security/#information-security-policy-exception-management-process&#34;&gt;Information Security Policy Exception Management Process&lt;/a&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
