Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review and apply all applicable security controls from our ATO to the system #85

Open
1 of 2 tasks
chelsgr opened this issue May 10, 2023 · 1 comment
Open
1 of 2 tasks

Comments

@chelsgr
Copy link

chelsgr commented May 10, 2023

Summary

When the CyHy system was established, there were heavy time drivers which did not allow for a full review to ensure all applicable security controls were fully implemented.

Motivation and context

A review should be conducted to ensure the appropriate security controls apply, e.g. in the areas of Identity Management, Access Control, Authentication, centralized logging, etc. The system should adhere to the same controls established for the COOL meeting our Authority to Operate (ATO) requirements. These requirements are defined in DHS 4300A and NIST 800-53.

There was also interest in supporting contextual information to justify a shared (COOL/CyHy) ATO and detail regarding shared controls applicable to CyHy. More specifically, that administrative access controls for the CyHy system match the ATO requirements previously established for the COOL. The recommendation provided was for users requiring access to the data to coordinate with enterprise service providers for authentication via their solutions.

Acceptance criteria

@chelsgr
Copy link
Author

chelsgr commented May 10, 2023

This ticket is intended to track a subset of work for the ATO renewal, tracked in: https://github.com/cisagov/cool-system-internal/issues/129

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: No status
Development

No branches or pull requests

1 participant