<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security_standard_acia on The GitLab Handbook</title>
    <link>https://handbook.gitlab.com/tags/security_standard_acia/</link>
    <description>Recent content in Security_standard_acia on The GitLab Handbook</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <atom:link href="https://handbook.gitlab.com/tags/security_standard_acia/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Access Requests (ARs)</title>
      <link>https://handbook.gitlab.com/handbook/security/corporate/end-user-services/access-requests/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://handbook.gitlab.com/handbook/security/corporate/end-user-services/access-requests/</guid>
      <description>&lt;span&#xA;  class=&#34;gl-label gl-label-text-light&#34;&#xA;  style=&#34;&#xA;    --label-background-color: #E24329;&#xA;    --label-inset-border: inset 0 0 0 2px #E24329;&#xA;  &#34;&#xA;&gt;&#xA;  &lt;span class=&#34;gl-link gl-label-link&#34;&gt;&#xA;    &lt;span class=&#34;gl-label-text&#34;&gt; Visibility: Audit &lt;/span&gt;&#xA;  &lt;/span&gt;&#xA;&lt;/span&gt;&#xA;&#xA;&lt;p&gt;Access Requests are owned by the IT team, while onboarding, offboarding and internal transition requests are owned by the People Operations Team.&lt;/p&gt;&#xA;&lt;p&gt;If you have any access requests related questions, please reach out to #it_help or the tool provisioner in Slack.&lt;/p&gt;&#xA;&lt;h2 id=&#34;access-requests-related-pages&#34;&gt;Access requests related pages&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#access-requests-related-pages&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://handbook.gitlab.com/handbook/security/corporate/end-user-services/access-requests/#application-specific-templates&#34;&gt;Frequently asked questions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gitlab.com/gitlab-com/www-gitlab-com/-/blob/master/data/tech_stack.yml&#34;&gt;Tech Stack&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://internal.gitlab.com/handbook/security/corporate/end-user-services/access-request/baseline-entitlements/&#34;&gt;Baseline Entitlements&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://internal.gitlab.com/handbook/security/corporate/end-user-services/access-request/temporary-service-providers/&#34;&gt;Temporary service providers access requests and onboarding&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;get-started&#34;&gt;Get Started&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#get-started&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;All open and closed ARs can be found in the &lt;a href=&#34;https://gitlab.com/gitlab-com/team-member-epics/access-requests/-/issues/&#34;&gt;access-requests project&lt;/a&gt;, and you can create a new issue &lt;a href=&#34;https://gitlab.com/gitlab-com/team-member-epics/access-requests/-/issues/new&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Access Review Procedure</title>
      <link>https://handbook.gitlab.com/handbook/security/security-assurance/security-compliance/access-reviews/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://handbook.gitlab.com/handbook/security/security-assurance/security-compliance/access-reviews/</guid>
      <description>&lt;span&#xA;  class=&#34;gl-label gl-label-text-light&#34;&#xA;  style=&#34;&#xA;    --label-background-color: #E24329;&#xA;    --label-inset-border: inset 0 0 0 2px #E24329;&#xA;  &#34;&#xA;&gt;&#xA;  &lt;span class=&#34;gl-link gl-label-link&#34;&gt;&#xA;    &lt;span class=&#34;gl-label-text&#34;&gt; Visibility: Audit &lt;/span&gt;&#xA;  &lt;/span&gt;&#xA;&lt;/span&gt;&#xA;&#xA;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;GitLab&amp;rsquo;s user access review is an important control activity required for internal and external IT audits, helping to minimize threats, and provide assurance that the right people have the right access to critical systems and infrastructure. This procedure details process steps and provides control owner guidance for access reviews.&lt;/p&gt;&#xA;&lt;h3 id=&#34;benefits-to-the-organization&#34;&gt;Benefits to the organization&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#benefits-to-the-organization&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Reduces security risk&lt;/li&gt;&#xA;&lt;li&gt;Identifies dormant and/or disabled accounts&lt;/li&gt;&#xA;&lt;li&gt;Ensures only required team members have access to a system&lt;/li&gt;&#xA;&lt;li&gt;Validates users who have changed roles have not retained access no longer relevant&lt;/li&gt;&#xA;&lt;li&gt;Ensures terminated team members no longer can access company systems&lt;/li&gt;&#xA;&lt;li&gt;Supports GitLab compliance and regulatory requirements which maintains customer trust&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;scope&#34;&gt;Scope&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#scope&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;h3 id=&#34;in-scope-systems&#34;&gt;In-Scope Systems&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#in-scope-systems&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Security Compliance performs Access Reviews for in-scope systems based on a subset of factors. Including:&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitLab Password Standards</title>
      <link>https://handbook.gitlab.com/handbook/security/policies_and_standards/password-standard/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://handbook.gitlab.com/handbook/security/policies_and_standards/password-standard/</guid>
      <description>&lt;span&#xA;  class=&#34;gl-label gl-label-text-light&#34;&#xA;  style=&#34;&#xA;    --label-background-color: #E24329;&#xA;    --label-inset-border: inset 0 0 0 2px #E24329;&#xA;  &#34;&#xA;&gt;&#xA;  &lt;span class=&#34;gl-link gl-label-link&#34;&gt;&#xA;    &lt;span class=&#34;gl-label-text&#34;&gt; Visibility: Audit &lt;/span&gt;&#xA;  &lt;/span&gt;&#xA;&lt;/span&gt;&#xA;&#xA;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;This document outlines information security password standards intended to protect GitLab information systems and other resources containing confidential (Red and Orange) GitLab data from unauthorized use, where technically feasible.&lt;/p&gt;&#xA;&lt;h2 id=&#34;scope&#34;&gt;Scope&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#scope&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Applies to all GitLab team members, contractors, advisors, and contracted parties interacting with GitLab computing resources and accessing confidential data.&lt;/p&gt;&#xA;&lt;h2 id=&#34;roles--responsibilities&#34;&gt;Roles &amp;amp; Responsibilities&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#roles--responsibilities&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Role&lt;/th&gt;&#xA;          &lt;th&gt;Responsibility&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;GitLab Team Members&lt;/td&gt;&#xA;          &lt;td&gt;Responsible for adhering to the requirements outlined in this standard&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Security&lt;/td&gt;&#xA;          &lt;td&gt;Responsible for defining and monitoring implementation of these standards for critical applications&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Security Management (Code Owners)&lt;/td&gt;&#xA;          &lt;td&gt;Responsible for approving significant changes and exceptions to these standards&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;h2 id=&#34;standard&#34;&gt;Standard&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#standard&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Constructing secure passwords and ensuring proper password management is essential. GitLab&amp;rsquo;s password standards are based, in part, on the recommendations by &lt;a href=&#34;https://pages.nist.gov/800-63-3/sp800-63b.html&#34;&gt;NIST 800-63B&lt;/a&gt;. To learn what makes a password truly secure, read this &lt;a href=&#34;https://medium.com/peerio/how-to-build-a-billion-dollar-password-3d92568d9277&#34;&gt;article&lt;/a&gt; or watch this &lt;a href=&#34;https://www.youtube.com/watch?v=vudZnjp5Uq0&amp;amp;t=19183&#34;&gt;conference presentation&lt;/a&gt; on password strength.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
