Skip to content

[Spike] Seek framework parameters from GitHub #54

@bzarboni1

Description

@bzarboni1

ISSUE

In order to satisfy the required ITSG-33 security controls, some of the information required to be proven is in the form of configuration that GitHub does not expose publicly.
The following is needed from GitHub:

  • How many login attempts before a user is locked?
    • How long is the user locked for?
  • Are there timeouts for user sessions? This information is not published.
  • Can GitHub tell the user the last time they logged in?
  • What profile settings for a user will cause an alert to be sent to the user's email?
  • ITSG requires that passwords are not reused for 24 generations. What is GitHub's internal value for this?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions