Skip to content

First part of AWS admin access approval process#5272

Draft
sihugh wants to merge 1 commit intomainfrom
new-cyberthumb
Draft

First part of AWS admin access approval process#5272
sihugh wants to merge 1 commit intomainfrom
new-cyberthumb

Conversation

@sihugh
Copy link
Contributor

@sihugh sihugh commented Oct 2, 2025

This guidance will be followed in due course by the process for responding to cyber-security alerts.

This will be followed in due course by the process for responders to pages.
@sihugh sihugh marked this pull request as ready for review October 7, 2025 12:12

If it is not urgent, wait until people are around. Privileged account use can be risky, so it's best to have a second pair of eyes anyway.

If you need access and it cannot wait, use Pagerduty to call the other on-call engineer. If they are not available, escalate to the GOV.UK Programme Escalations rota.
Copy link
Contributor

@AgaDufrat AgaDufrat Oct 8, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I recognise this will be super rare but it would be good to clarify what we are calling them for (to approve the cyber thumb or to shadow/pair on the task). The GOV.UK Programme Escalations person may not be technical so perhaps it's to sense check your privileged access action and confirm you are permitted to do it.

@@ -0,0 +1,44 @@
---
owner_slack: "#govuk-platform-engineering"
title: Obtain approval before using the fulladmin role on AWS
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Side comment. I think we should email the GOV.UK Technology Members about this new process. Slack hasn't been always the best in communicating "breaking" changes.

@jasonBirchall jasonBirchall marked this pull request as draft October 27, 2025 09:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants