ASSOCIATED DRATA CONTROL
This test is part of the Terminated Employee Access Revoked Within One Business Day control that ensures access to infrastructure and code review tools is removed from terminated employees within one business day.
WHAT TO DO IF A TEST FAILS
This test examines two things:
The System Access Control policy is in place and approved
Former employees have an Access Revoked date for their linked VCS Managed Account
Ensure your System Access Control policy is in place and approved by the owner.
If Drata finds terminated/separated employees that still have access to the company Version Control System the test will fail. With a failed test you will receive a list of terminated/separated employees that still retain access.
To remediate a failed test, you will need to revoke the user's Version Control System access or mark them as not terminated on the 'Personnel' page within Drata.