-
Notifications
You must be signed in to change notification settings - Fork 4
As security system, I should ensure AC-2(8) Dynamic account management #237
Copy link
Copy link
Open
Labels
line:mvfAction or item managed via the MVF production line dedicated to prototypes deliveryAction or item managed via the MVF production line dedicated to prototypes deliverypriority:highHigh priority for treatmentHigh priority for treatmentstatus:confirmedThe will to process the item/request of work is confirmed and acceptedThe will to process the item/request of work is confirmed and accepted
Milestone
Metadata
Metadata
Assignees
Labels
line:mvfAction or item managed via the MVF production line dedicated to prototypes deliveryAction or item managed via the MVF production line dedicated to prototypes deliverypriority:highHigh priority for treatmentHigh priority for treatmentstatus:confirmedThe will to process the item/request of work is confirmed and acceptedThe will to process the item/request of work is confirmed and accepted
Type
Fields
Give feedbackNo fields configured for issues without a type.
Projects
Status
Coding
FTEST_198: https://www.notion.so/cybnity/198-6dde495085b94fb3a1e4ee01d46b4d44?pvs=4
PRD: https://www.notion.so/cybnity/AC-2-8-Dynamic-account-management-72d42a96723c48e5b254c59fd24b6bc8?pvs=4
Approaches for dynamically creating, activating, managing, and deactivating system accounts rely on automatically provisioning the accounts at runtime for entities that were previously unknown. Organizations plan for the dynamic management, creation, activation, and deactivation of system accounts by establishing trust relationships, business rules (e.g security missions), and mechanisms with appropriate authorities (e.g security team owner; sub-division team) to validate related authorizations and privileges.
AC-2(8): Create, activate, manage, and deactivate [Assignment: organization-defined system accounts] dynamically.
Family : ACCESS CONTROL
Used capabilities: Stakeholders and responsibilities UI Module server
USE CASES DESIGN
Registration flow and process (activities diagram about global registration flow with scenario identification)
PROTOTYPING
Use case and home screen design relative to new Tenant and root account (tenant owner):
CODING
TEST & NON REGRESSION CAMPAIGN
DOCUMENTATION
Component: Application System Security Control Implementation Component
Implementation deployable system: Access control & sso server
Technology layer: user interface area
Technologies: nodeJS, keycloack, java, javascript, ReactJS