Explanation:
Detects events where a dormant user-managed service account triggered an action. In this context, a service account is considered dormant if it has been inactive for more than 180 days.
Resolution:
Further investigation is required to see which action to be performed.
The GCP Security team will need to evaluate based on the actions below:
| Actions | Follow up | ||
|---|---|---|---|
Open the Initial Access: Dormant Service Account Action finding, as directed in Reviewing findings. Under What was detected:
Check with the application owner that the service account in the Principal email field whether the legitimate owner conducted the action.
| If not exception - Inform application owner Exception case - Don't have to inform application owner. |
See the table below for recommended action after investigation.
| Yes / No | Action |
|---|---|
| Inform application owner. | Inform the owner about the activity and update the JIRA ticket's rememdiation action to be "Owner is being informed" and closed the ticket. |
| Don't have to inform application owner. | Update the JIRA ticket's rememdiation action to be "False positive. Triggered by pipeline." and closed the ticket. |
The best way to get IT support is to use the new
Service One Platform.