-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
ISSUE
In order to satisfy the required ITSG-33 security controls, some of the information required to be proven is in the form of configuration that GitHub does not expose publicly.
The following is needed from GitHub:
- How many login attempts before a user is locked?
- How long is the user locked for?
- Are there timeouts for user sessions? This information is not published.
- Can GitHub tell the user the last time they logged in?
- What profile settings for a user will cause an alert to be sent to the user's email?
- ITSG requires that passwords are not reused for 24 generations. What is GitHub's internal value for this?
Metadata
Metadata
Assignees
Labels
No labels