Project

General

Profile

Actions

communication #160508

open

RFC: Disable stale Heroes accounts

Added by crameleon about 1 month ago. Updated about 20 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Compliance
Target version:
-
Start date:
2024-05-18
Due date:
% Done:

0%

Estimated time:

Description

To reduce the intrusion surface from credentials sitting with people who no longer use them, I propose to:

  • contact users who did not authenticate to the Heroes VPN for >= 6 months
  • if no response + login within 2 weeks, disable Heroes IDM account and revoke the corresponding VPN client certificate

This would be manifested in the infrastructure policy, and could be partially automated.

Actions

Also available in: Atom PDF