Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create GSA-pages.md #3814

Merged
merged 35 commits into from
Apr 17, 2024
Merged
Changes from 1 commit
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
11f91ac
Create tts-pages.md
JJediny Feb 28, 2024
d225b31
Updates based on review and spellcheck
JJediny Feb 29, 2024
865c857
update-to-confirm-or-add-to-touchpoints
JJediny Mar 1, 2024
bc0dc1d
Updates based on Feedback so far
JJediny Mar 2, 2024
03cbc1d
Update tts-pages.md
JJediny Mar 2, 2024
f240666
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Mar 4, 2024
b22bbdf
rename back to gsa-pages
JJediny Mar 11, 2024
d748a53
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Mar 11, 2024
6e1236e
change request link
JJediny Mar 11, 2024
46ca3b9
Merge branch 'gsa-pages-atu-WIP' of https://github.com/18F/handbook i…
JJediny Mar 11, 2024
548b763
minor edits
JJediny Mar 12, 2024
2761926
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Mar 19, 2024
bdc6643
change blockqoutes to use handbook alert components where appropriate
JJediny Mar 22, 2024
f29edd6
Change capatalization based on feedback
JJediny Mar 22, 2024
531631c
Change passive voice based on
JJediny Mar 22, 2024
70052b6
add to whom
JJediny Mar 22, 2024
7b60847
add to by whom
JJediny Mar 22, 2024
2a7e937
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Mar 22, 2024
05615da
swap banner order and remove multiple links to pages
JJediny Mar 22, 2024
ae99f48
remove more capitalization
JJediny Mar 22, 2024
f450c66
use h4 for low systems alerts to avoid adding to in page nav
drewbo Mar 22, 2024
2af882e
fix link, small formatting
drewbo Mar 22, 2024
429302e
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Mar 29, 2024
1e9358e
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Apr 8, 2024
81e91cf
Delete tts-pages.md
JJediny Apr 11, 2024
8a97bbf
Updates based on outreach feedback
JJediny Apr 12, 2024
d3450b2
Change the workflow
JJediny Apr 15, 2024
6157dff
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Apr 15, 2024
b3e7776
add mailto link
JJediny Apr 15, 2024
af8b367
Merge branch 'gsa-pages-atu-WIP' of https://github.com/18F/handbook i…
JJediny Apr 15, 2024
d63069c
add dns slack link
JJediny Apr 15, 2024
f6d2246
change to form entry
JJediny Apr 15, 2024
4b509e6
Merge branch 'main' into gsa-pages-atu-WIP
JJediny Apr 17, 2024
53659a5
Add DLP link upfront
JJediny Apr 17, 2024
e25fb2c
Merge branch 'gsa-pages-atu-WIP' of https://github.com/18F/handbook i…
JJediny Apr 17, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Updates based on outreach feedback
JJediny committed Apr 12, 2024

Verified

This commit was signed with the committer’s verified signature.
marcelstanley Marcel Moura
commit 8a97bbfa6da371584efaf799f1a98d3f647c2f62
Original file line number Diff line number Diff line change
@@ -12,6 +12,12 @@ redirect_from:

"GSA Pages" is a **GSA only Authority to Operate (ATO)** of [cloud.gov's FEDRAMP Authorization](https://marketplace.fedramp.gov/products/F1607067912) of their [cloud.gov Pages](https://pages.cloud.gov) service. As such, it adds the Security Controls around the source code and contents for the website (e.g. Github). It provides **GSA employees** with a fast and secure approach to getting a web presence for your projects/programs.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍


## Launching a Website at GSA
- Confirm your website is listed on [https://touchpoints.digital.gov](https://touchpoints.digital.gov)
- if not listed, [complete a new website request](https://touchpoints.app.cloud.gov/admin/websites/new)

Prior to standing up a site with GSA Pages, you will need a domain or subdomain. To obtain a new domain or subdomain with GSA, approval is needed by GSA Leadership and Office of Customer Experience in Touchpoints.

## Launching a cloud.gov Pages Website

- Identify a Federal GSA Employee as the **GSA Website Manager**
@@ -27,15 +33,18 @@ redirect_from:
- Submit a pull request to add your repository to our Github configuration scanner to [GSA](https://github.com/GSA/.allstar/blob/main/allstar.yaml) or [GSA-TTS](https://github.com/GSA-TTS/.allstar/blob/main/allstar.yaml)
- Create a [`SECURITY.md` file](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) - [Example](https://github.com/GSA-TTS/.allstar/blob/main/SECURITY.md)
- Follow GSA's [Digital Lifecycle Program](https://insite.gsa.gov/employee-resources/communications/websites/strategy-policy-and-standards/digital-lifecycle-program?term=DLP) for the Website
- Confirm your website is listed on [https://touchpoints.digital.gov](https://touchpoints.digital.gov)
- if not submit a [new website request](https://touchpoints.app.cloud.gov/admin/websites/new)

## Authority to Use (ATU) Review
Submit an [Authority to Use (ATU) Request](https://github.com/GSA-TTS/gsa-pages/issues/new/choose)
1. Review [GSA Pages Security Review and Approval Process](https://insite.gsa.gov/system/files/GSA-Pages-Security-Review-and-Approval-Process-%5BCIO-IT-Security-20-106-Revision-2%5D-03-08-2024_0.pdf)
1. Submit an **Authority to Use (ATU) Request** [in Github](https://github.com/GSA-TTS/gsa-pages/issues/new/choose) or [in Google Form]()

- Resolve any Critical or High security findings from security scanners
- `[email protected]' will:
- Create a Google Group for your website
- Conduct a review of the repository using [GSA Pages Security Review](https://insite.gsa.gov/system/files/GSA-Pages-Site-Review-and-Approval-Template-03-08-2024.docx)
- Notify the Website Manager of any missing information or security findings

Once the ATU review is completed the **GSA Website Manager** will be sent an ATU Approval package for signature. The **GSA Website Manager** will be responsible for managing Security Findings over the lifecycle of the Website.
Once the ATU review is completed the **GSA Website Manager** will be sent an ATU Approval package for signature in Docusign. The **GSA Website Manager** will be responsible for managing Security Findings over the lifecycle of the Website using the Google Group created to manage communications.

## Maintaining Approved Sites
Sites hosted on GSA Pages are required to have their URLs scanned in accordance with CIO-IT Security-06-30: Managing Enterprise Cybersecurity Risk and GSA’s parameter for National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, control RA-5, Vulnerability Scanning.