About security incidents
A security incident is an event that could compromise your enterprise's accounts, code, or other data. Examples include compromised accounts, leaked credentials, unexpected access, or unauthorized changes.
Investigating and responding to an incident is self-service. Before an incident occurs, enable enterprise audit log streaming, API request event streaming, and source IP address disclosure. Retain the logs in storage that your incident responders can access.
重要
Audit log streaming only includes activity from the time you enable it. Enabling it during an incident will not recover earlier activity.
For guidance on preparing for and responding to an incident, see:
How GitHub 支持 can help
重要
When an incident occurs, follow your incident response procedures immediately. Focus first on containing the threat with actions appropriate to the incident, such as restricting access and revoking or rotating compromised credentials.
For enterprise-level containment options, see 锁定企业中的单点登录 and 在企业中撤销授权或删除凭据.
GitHub 支持 can answer questions about GitHub's features and the data available to you, so you can investigate and analyze the activity yourself. GitHub 支持 does not investigate or analyze on your behalf.
If you need guidance using these features or want to request a feature, see 创建支持工单.
GitHub 支持 handles all security-related matters in writing through support tickets.
No managed incident response service
GitHub 支持 does not join or lead your incident response process. To investigate and contain a threat, use GitHub's audit log, security, and access-management tools.
No log preservation
GitHub 支持 cannot fulfill requests to preserve logs or audit data, extend their retention periods, or place them on hold for your investigation. Opening a support ticket does not change how long data remains available. To retain data for an investigation, export it while it is available or configure audit log streaming in advance to storage you control.
Further reading
- Full exposure: a practical approach to handling sensitive data leaks in the GitHub blog
- GitHub Enterprise Cloud Trust Center for GitHub's security, privacy, and compliance information
- GitHub security blog for security research, announcements, and best practices from GitHub
- GitHub Bug Bounty to report a security vulnerability you find in a GitHub product