Skip to content

Commit 476b1e8

Browse files
authored
Merge pull request #46149 from github/repo-sync
Repo sync
2 parents b6a7035 + afc156d commit 476b1e8

20 files changed

Lines changed: 209 additions & 22 deletions

File tree

‎content/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise.md‎

Lines changed: 39 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,46 @@ contentType: how-tos
1717
category:
1818
- Monitor and audit your enterprise
1919
---
20-
{% data reusables.audit_log.retention-periods %}
2120

21+
{% ifversion ghec %}
22+
23+
There are several ways to access and retain audit log data for your enterprise:
24+
25+
* **Web interface**: View recent activity in your enterprise settings. See [Viewing the enterprise's audit log via the web interface](#viewing-the-enterprises-audit-log-via-the-web-interface).
26+
* **JSON/CSV exports**: Download a file of audit log activity. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/exporting-audit-log-activity-for-your-enterprise).
27+
* **REST API endpoint**: Query audit log events programmatically. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/using-the-audit-log-api-for-your-enterprise).
28+
* **Streaming to an external system**: Deliver events continuously to a system that your incident responders can access and query. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).
29+
30+
Each method exposes a different subset of your audit log data. For the full list of events, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise).
31+
32+
## Audit log data available by access method
33+
34+
{% data reusables.audit_log.events-data-retention-enterprise %}
35+
36+
For enterprises that use {% data variables.product.prodname_emus %}, the enterprise audit log also includes user events. For a list of these user events, see [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/security-log-events).
37+
38+
To retain Git events beyond their availability in the audit log, save them to external storage before they expire. Configure audit log streaming in advance to collect events continuously.
39+
40+
Git event exports do not include events initiated through the web interface or the REST or GraphQL APIs. For example, when someone merges a pull request in the web interface, the resulting push to the base branch is missing from the export.
41+
42+
`api.request` events are available only in streamed enterprise audit logs, and only when the option to stream API request events has been enabled. For more information, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#enabling-audit-log-streaming-of-api-requests).
43+
44+
> [!IMPORTANT]
45+
> {% data reusables.audit_log.streaming-not-retroactive %}
46+
47+
## Preparing for an incident response
48+
49+
Enable enterprise audit log streaming, API request event streaming, and source IP address disclosure to prepare for incident response. Without all three features enabled, responders will have critical visibility gaps when investigating incidents affecting your enterprise or its organizations. Set an appropriate retention period for the streamed logs and ensure incident responders can access them.
50+
51+
For setup instructions, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming), [Enabling audit log streaming of API requests](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#enabling-audit-log-streaming-of-api-requests), and [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/displaying-ip-addresses-in-the-audit-log-for-your-enterprise).
52+
53+
{% data reusables.support.security-incident-expectations %}
54+
55+
{% endif %}
56+
57+
## Viewing the enterprise's audit log via the web interface
58+
59+
{% data reusables.audit_log.retention-periods %}
2260
{% data reusables.enterprise-accounts.access-enterprise %}
2361
{% data reusables.enterprise-accounts.settings-tab %}
2462
{% data reusables.enterprise-accounts.audit-log-tab %}

‎content/code-security/how-tos/manage-security-alerts/manage-dependabot-alerts/view-dependabot-alerts.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -164,7 +164,7 @@ You can view all open alerts, and you can reopen alerts that have been previousl
164164

165165
## Reviewing the audit logs for {% data variables.product.prodname_dependabot_alerts %}
166166

167-
When a member of your organization {% ifversion not fpt %}or enterprise {% endif %}performs an action related to {% data variables.product.prodname_dependabot_alerts %}, you can review the actions in the audit log. For more information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log){% ifversion not fpt %} and [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise).{% else %}.{% endif %}
167+
When a member of your organization {% ifversion not fpt %}or enterprise {% endif %}performs an action related to {% data variables.product.prodname_dependabot_alerts %}, you can review the actions in the audit log. For more information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-organizations-audit-log-via-the-web-interface){% ifversion not fpt %} and [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise).{% else %}.{% endif %}
168168

169169
![Screenshot of the audit log showing Dependabot alerts.](/assets/images/help/dependabot/audit-log-ui-dependabot-alert.png)
170170

‎content/code-security/reference/security-incident-response/investigation-tools.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,7 @@ Read access to the repository.
5757

5858
* [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise)
5959
* [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/audit-log-events-for-your-organization)
60+
* [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/reviewing-your-security-log)
6061
* [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/security-log-events){% ifversion ghec %}
6162
* [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/identifying-audit-log-events-performed-by-an-access-token){% endif %}
6263

@@ -147,6 +148,7 @@ Read access to the repository.
147148

148149
* [AUTOTITLE](/code-security/concepts/security-at-scale/security-overview)
149150
* [AUTOTITLE](/code-security/how-tos/view-and-interpret-data/analyze-organization-data/viewing-security-insights)
151+
* [AUTOTITLE](/code-security/how-tos/view-and-interpret-data/analyze-organization-data/find-insecure-repositories)
150152

151153
### Notes and limitations
152154

‎content/code-security/tutorials/secure-your-organization/prepare-for-a-security-incident.md‎

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,10 +27,19 @@ These controls are critical for incident response, compliance, and operational t
2727

2828
### Audit log streaming
2929

30-
You should stream the enterprise audit logs to a Security Information and Event Management (SIEM) system. This keeps a copy of your audit log data (including both audit events and Git events) in a system where you can run complex queries across large volumes of data and retain data beyond default retention periods.
30+
You should stream the enterprise audit logs, including API request events, to a Security Information and Event Management (SIEM) system. This keeps a copy of your audit log data (including web, Git and API events) in a system where you can run complex queries across large volumes of data and retain data beyond default retention periods.
31+
32+
> [!IMPORTANT]
33+
> {% data reusables.audit_log.streaming-not-retroactive %}
3134
3235
This is critical in an incident because some high-value events are not visible in the {% data variables.product.github %} audit log web UI, and logs are only available for a limited time unless you export and retain them externally.
3336

37+
{% ifversion ghec %}
38+
39+
To compare event availability and retention across access methods, see [Audit log data available by access method](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise#audit-log-data-available-by-access-method).
40+
41+
{% endif %}
42+
3443
With streamed logs, enterprise and organization owners can independently investigate activity from users, apps, tokens, and SSH keys, instead of depending on ad hoc data collection during an active response.
3544

3645
To set up audit log streaming, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).
@@ -53,9 +62,9 @@ Enterprises on {% data variables.product.prodname_ghe_cloud %} can enable IP add
5362

5463
### Retain identity provider logs
5564

56-
If your enterprise uses SAML or OIDC authentication, adopt a similar retention strategy for your IdP logs.
65+
If your enterprise or organizations use SAML or OIDC authentication, adopt a similar retention strategy for your identity provider (IdP) logs.
5766

58-
Retained IdP logs help you investigate authentication activity and review provisioning and deprovisioning events over longer time windows, including incidents that unfold over months.
67+
Retained IdP logs help you investigate authentication activity and review provisioning, deprovisioning, and group membership changes over longer time windows. This is especially important if you use SCIM provisioning or need to investigate activity from several months ago.
5968

6069
## Familiarize yourself with tooling, limitations and common investigation areas
6170

‎content/code-security/tutorials/secure-your-organization/respond-to-a-security-incident.md‎

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -23,12 +23,13 @@ This guide walks you through how to respond to a security incident, outlining th
2323
2424
### Prerequisites
2525

26-
Ideally, you have **audit log streaming** and **source IP address visibility** already enabled for the enterprise (streaming the data to a security information and event management (SIEM) system) and you have access to that data. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).
26+
Investigating and responding to an incident is self-service. Before an incident occurs, enterprise owners should enable enterprise audit log streaming, API request event streaming, and source IP address disclosure. Without all three features enabled at the enterprise level, responders will have critical visibility gaps when investigating incidents affecting the enterprise or its organizations. Enterprise owners should also set an appropriate retention period for the streamed logs and ensure incident responders can access them. See [AUTOTITLE](/code-security/tutorials/secure-your-organization/prepare-for-a-security-incident#set-up-critical-tools-in-advance).
2727

2828
### Throughout your response
2929

3030
As you progress through your response, make sure that you:
31-
* **Preserve evidence**: Take screenshots of suspicious activity, export logs or query results, and save copies of affected files or code before cleanup.
31+
32+
* **Capture available evidence**: Take screenshots of suspicious activity, export logs or query results while they are available, and save copies of affected files or code before cleanup. Opening a support ticket does not preserve logs or extend their retention period. {% ifversion ghec %}For information about {% data variables.contact.github_support %}'s role, see [AUTOTITLE](/support/learning-about-github-support/understanding-how-github-support-can-help-during-a-security-incident).{% endif %}
3233
* **Keep a record**: Document your findings (for example, times, dates, Indicators of Compromise (IoCs), repositories affected) and record each decision you take.
3334
* **Communicate**: Notify relevant stakeholders (such as security leads and engineering managers, as well as legal and privacy teams if sensitive data is at risk) and keep them updated.
3435

@@ -74,6 +75,7 @@ The following {% data variables.product.github %} tools and surfaces can help.
7475
For details on each tool, see [AUTOTITLE](/code-security/reference/security-incident-response/investigation-tools).
7576

7677
The validation phase can be **quick**:
78+
7779
* Aim to gather enough evidence to determine whether the signal is likely to be a **real** and **active** threat.
7880
* If you can't quickly rule out the signal as a false positive, assume it's real.
7981
* Deep investigation can be performed later.
@@ -120,6 +122,7 @@ For exposed or exploited credentials, the most immediate action you can take is
120122
There are additional options for blocking credential access. For a full list by credential type, see [AUTOTITLE](/organizations/managing-programmatic-access-to-your-organization/github-credential-types).
121123

122124
{% ifversion single_user_cred_revocation %}
125+
123126
* **Revoke or delete credentials for a specific user**
124127

125128
If you've identified a specific compromised account, enterprise or organization owners on {% data variables.product.prodname_ghe_cloud %} can revoke SSO authorizations for that individual user. For enterprises with {% data variables.product.prodname_emus %}, you can also delete credentials entirely. This is less disruptive than bulk actions while still containing the threat. See [AUTOTITLE](/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens#taking-action-against-individual-members).
@@ -129,6 +132,7 @@ For exposed or exploited credentials, the most immediate action you can take is
129132
If the incident is limited to one credential type, such as {% data variables.product.pat_v1_plural %}, enterprise or organization owners can revoke SSO authorizations or delete credentials of that type only, across all members, using the {% data variables.product.github %} UI{% ifversion ghec %} or REST API{% endif %}. This targets the affected credential type without disrupting other credentials. See [AUTOTITLE](/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens#taking-action-against-a-specific-credential-type).
130133

131134
{% endif %}
135+
132136
* **Emergency actions (major incident)**
133137

134138
Enterprise{% ifversion single_user_cred_revocation %} and organization{% endif %} owners on {% data variables.product.prodname_ghe_cloud %} can take bulk emergency actions to lock down access across their enterprise{% ifversion single_user_cred_revocation %} or organization{% endif %}. For enterprises with {% data variables.product.prodname_emus %}, this includes **deleting all user tokens and keys**. These are high-impact actions that will break automations and should be reserved for major incidents. See [AUTOTITLE](/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents).
@@ -162,9 +166,9 @@ To restrict access to the enterprise, organization or repository, there are seve
162166
* **Stop malicious workflow runs**
163167

164168
If you suspect that a {% data variables.product.prodname_actions %} workflow or runner is being used as part of an active attack, you can take the following actions:
165-
* Cancel in-progress workflow runs for an affected repository. See [AUTOTITLE](/actions/how-tos/manage-workflow-runs/cancel-a-workflow-run).
166-
* Disable {% data variables.product.prodname_actions %} for an affected repository in an organization, or for a specific organization. See [AUTOTITLE](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization) (organization owners) and [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise) (enterprise administrators).
167-
* Remove self-hosted runners. See [AUTOTITLE](/actions/how-tos/manage-runners/self-hosted-runners/remove-runners).
169+
* Cancel in-progress workflow runs for an affected repository. See [AUTOTITLE](/actions/how-tos/manage-workflow-runs/cancel-a-workflow-run).
170+
* Disable {% data variables.product.prodname_actions %} for an affected repository in an organization, or for a specific organization. See [AUTOTITLE](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization) (organization owners) and [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise) (enterprise administrators).
171+
* Remove self-hosted runners. See [AUTOTITLE](/actions/how-tos/manage-runners/self-hosted-runners/remove-runners).
168172

169173
* **Disable webhooks**
170174

@@ -214,6 +218,7 @@ Even if you're not certain a credential was compromised, rotate it if there's an
214218
You will need to check for persistence mechanisms that the attacker may have established to maintain access even after your initial containment actions.
215219

216220
This includes, but isn't limited to, checking for things like:
221+
217222
* Suspicious or unfamiliar workflow files that may have been added or modified.
218223
* New webhooks pointing to unfamiliar domains.
219224
* New self-hosted runners.

‎content/codespaces/managing-codespaces-for-your-organization/reviewing-your-organizations-audit-logs-for-github-codespaces.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ category:
1313
- Manage codespaces for your organization
1414
---
1515

16-
When any member of your organization performs an action related to {% data variables.product.prodname_github_codespaces %}, you can review the actions in the audit log. For information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log).
16+
When any member of your organization performs an action related to {% data variables.product.prodname_github_codespaces %}, you can review the actions in the audit log. For information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-organizations-audit-log-via-the-web-interface).
1717

1818
![Screenshot of the "Audit log" page for an organization, showing the "Recent events" list.](/assets/images/help/codespaces/codespaces-audit-log-org.png)
1919

‎content/copilot/how-tos/administer-copilot/manage-for-enterprise/use-managed-settings/get-started.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ contentType: how-tos
1414
category:
1515
- Configure Copilot
1616
- Manage Copilot for a team
17+
docsTeamMetrics:
18+
- ai-governance
1719
---
1820

1921
With enterprise managed settings, you can centrally define and distribute configuration settings for {% data variables.product.prodname_copilot %} to supported clients. This ensures everyone works within the guardrails you define, with the option to specialize settings for different teams. For example, you can block agents from performing sensitive operations, install approved agent plugins, or ensure that sessions run in a sandbox.

0 commit comments

Comments
 (0)