Security/Fundamentals: Difference between revisions

Automated sync from https://github.com/mozilla/wikimo_opsec
(Automated sync from https://github.com/mozilla/wikimo_opsec)
(Automated sync from https://github.com/mozilla/wikimo_opsec)
Line 30: Line 30:
|Decentralized user account management refers to user account management which is not driven by the source of truth for the user's account. Examples of this are:
|Decentralized user account management refers to user account management which is not driven by the source of truth for the user's account. Examples of this are:
* Manual user account creation by administrators.
* Manual user account creation by administrators.
* Automated user account creation from scripting or configuration management that creates accounts based on a static
* Automated user account creation from scripting or configuration management that creates accounts based on a static list of users.
* list of users.
This practice is discouraged because:
This practice is discouraged because:
* When a user's access status changes due to leaving the company or changing teams, the associated change in the system
* When a user's access status changes due to leaving the company or changing teams, the associated change in the system
Confirmed users
502

edits