GitHub for Government
Welcome! This site publishes the repository documentation in an easy-to-share format.
- GitHub for Government
- Questions Auditors Commonly Ask (and How to Answer Them)
- “Is GitHub a production system?”
- “Can someone accidentally change something critical?”
- “Is there an audit trail?”
- “Can changes be made without approval?”
- “Can someone delete or alter history?”
- “Who controls access?”
- “Is GitHub secure?”
- “Does using GitHub violate records management requirements?”
- “Is this compliant with our regulatory framework?”
- “Can GitHub be used with sensitive data?”
- “What happens if something goes wrong?”
- “Who is accountable for decisions?”
- “Why not just use shared drives or email?”
- “Does transparency increase risk?”
- “What is the risk of not using something like GitHub?”
- Summary for Meetings
- Common GitHub Terms
- GitHub Terms for Auditors & Compliance
- How GitHub Supports Internal Controls
- Control Objective: Change Authorization
- Control Objective: Change Documentation
- Control Objective: Traceability
- Control Objective: Separation of Duties
- Control Objective: Access Management
- Control Objective: Monitoring and Oversight
- Control Objective: Evidence Retention
- Control Objective: Error Detection and Recovery
- What GitHub Does Not Control
- Control Effectiveness Depends On
- Summary for Internal Control Owners
- Participating Safely on GitHub
- A note before you begin
- 1. Reading content (zero risk)
- 2. Creating an Issue (asking a question or raising a concern)
- 3. Suggesting an edit (browser-based, no local tools)
- 4. Forking a repository (making your own copy)
- 5. Opening a Pull Request (requesting a change)
- 6. Review and approval
- 7. Permissions and roles
- 8. What happens if a mistake is made
- 9. When to pause and ask questions
- 10. Summary
- Why this matters in government environments
- Optional: GitHub Command Line (CLI)