インシデント対応のためのセルフサービス資格情報取り消し機能の追加
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
GitHub Changelog
GitHub は、侵害されたアカウントや盗まれた資格情報への迅速な対応のため、GitHub Enterprise の管理者が特定のユーザーのすべての資格情報を即座に取り消す「ブレイクグラス」機能を新設した。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
侵害されたアカウントや盗まれた認証情報を伴うセキュリティインシデントに対して迅速に対応するため、GitHub Enterprise の所有者は、特定のユーザーのすべての認証情報を即座に失効させる新しい「緊急時用(break-glass)」機能を現在利用できます。これは、以前にリリースされたインシデント対応用の企業全体での認証情報管理ツールを基盤としています。
今回のリリースにより、企業所有者および「企業の認証情報の管理」という細粒度権限を持つメンバーは、企業内のすべてのユーザーまたは特定のユーザーに対して、以下の一括操作を実行できるようになりました:
SSO 認証情報を失効させる(企業全体でのユーザー認証情報:パーソナルアクセストークン、SSH キー、OAuth トークン)。
SSO 認証情報がなくても、企業全体でユーザーのトークンと SSH キーを削除する。この操作は EMU アカウントのみで利用可能です。
特定の組織内でのユーザー認証情報の SSO 認証情報を一覧表示し、失効させる。これらの操作は、組織レベルの REST API を通じてプログラム経由でのみサポートされています。
さらに、Settings -> Credentials ビューの一部として、個別の企業メンバー向けの新しいセルフサービス失効体験を導入しました。これにより、以下が可能になります:
自分の個人アカウントによって生成または SSO 経由で承認された認証情報の数を閲覧する。
トークンやキーを一つずつ確認することなく、すべての認証情報と認証を一括でセルフサービスで失効または削除する。
エンタープライズの所有者および影響を受けたユーザーは、上記の各新しいアクションによって生成された監査ログと電子メール通知を通じて、取り消しおよび削除された認証情報の詳細を確認できます。
詳しくは、エンタープライズにおけるセキュリティインシデントへの対応方法や GitHub 認証情報リファレンスに関する当社のドキュメントをご覧ください。
GitHub コミュニティ内のディスカッションに参加してください。
本記事「Self-service credential revocation for incident response」は、The GitHub Blog に最初に掲載されました。
原文を表示
For a timely response to security incidents involving compromised accounts or stolen credentials, GitHub Enterprise owners can now use new “break-glass” capabilities to instantly revoke all credentials for a given user. This builds on the enterprise-wide credential management tools for incident response released earlier.
With this release, enterprise owners and members with the fine-grained permission Manage enterprise credentials can trigger the following bulk actions for all users or for a specific user in their enterprise:
Revoke SSO authorizations for user credentials (personal access tokens, SSH keys, and OAuth tokens) across your enterprise.
Delete user tokens and SSH keys across your enterprise, even if they don’t have an SSO authorization. This action is available only for EMU accounts.
List and revoke SSO authorizations for user credentials across a specific organization. These actions are only supported programmatically through the org-level rest APIs.
Additionally, we have introduced a new self-service revocation experience for individual enterprise members as part of Settings -> Credentials view, which enables you to:
Review counts of credentials that are generated or authorized via SSO by your personal account.
Self-service revoke or delete all of your credentials and authorizations in a single action without going token-by-token or key-by-key.
Enterprise owners and affected users can review details about revoked and deleted credentials via audit logs and email notifications generated by each of the new actions above.
To learn more, see our documentation around how to respond to security incidents in your enterprise and GitHub credentials reference.
Join the discussion within GitHub Community.
The post Self-service credential revocation for incident response appeared first on The GitHub Blog.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み