View a markdown version of this page

GAMESEC07-BP02 Ban accounts that are associated with bad actors - Games Industry Lens

GAMESEC07-BP02 Ban accounts that are associated with bad actors

If left unmitigated, abusive behaviors in a game can continue to have a negative impact on the gaming experience for others and should be mitigated as soon as possible. Implement a process to impose bans or other forms of restrictions on bad actors who are confirmed to be in violation of your terms of service. 

Level of risk exposed if this best practice is not established: High

Implementation guidance

Typically, the rules and evaluation process for determining the circumstances for imposing these types of restrictions will be determined by personnel such as a player community team or trust and safety team within your organization. After you've flagged bad actors, run a pre-determined workflow to act on the identified players. 

For example, AWS Step Functions and AWS Lambda functions can be used to run an automated workflow that accepts a batch of player accounts as input. The workflow then updates entries in an Amazon DynamoDB table called Bans, which can include details about the player account, the ban reason, and duration. 

Depending on the design of your game and account management system and the type of abuse that you encounter from bad actors, maintain a banning system of record that is separate from your account management system. You may not want to turn off the player's account from your account management system, opting instead to simply turn off their ability to play your game. This can be useful in situations where the player's account credentials are used to access multiple games with different terms of service or policies.

Implementation steps

  • Define and enforce policies for responding to abusive behaviors from bad actors.

  • Use AWS services to automate your responses to bad actors. 

Resources