Skip to content

Latest commit

 

History

History
34 lines (24 loc) · 8.78 KB

01_Protect-user-accounts-and-identities.md

File metadata and controls

34 lines (24 loc) · 8.78 KB

Protect user accounts and identities

(Back)

Objective

Protect User Accounts and Identities.

Applicable Service Models

  • IaaS, PaaS, SaaS
Mandatory Requirements Validation
  • Confirm that MFA is implemented as per GC guidance through screenshots, compliance reports, or compliance check enabled through a reporting tool for all user accounts.
  • Confirm that digital policies are in place to ensure that MFA configurations are enforced.
  • Confirm and report the count of Root/Global administrator registered (should have at least two and no more than five).
  • Configure alerting to ensure the prompt detection of a potential compromise, in accordance with the GC Event Logging Guidance.
  • Confirm if monitoring and auditing is implemented for all user accounts.
  • Confirm alert notification to the authorized personnel is implemented for flagging misuse, or suspicious activities for all user accounts.
  • Use separate dedicated accounts for highly privileged roles (e.g. domain admins, global admins, root, and any domain admin equivalent access) when administering cloud services to minimize the blast radius.
  • Provide evidence that dedicated user accounts are used for administration (e.g., privileged access).
Additional Considerations
None

References

  1. SPIN 2017-01, subsection 6.2.3
  2. CSE Top 10 #3
  3. Refer to the Recommendations for Two-Factor User Authentication Within the Government of Canada Enterprise Domain
  4. Refer to the GC Multi-Factor Authentication (MFA) Strategy Paper
  5. Refer to the Directive on Service and Digital, Appendix G: Standard on Enterprise Information Technology Service Common Configurations - Account Management Configuration Requirements
  6. Refer to the GC Event Logging Guidance.
  7. Refer to ITSP.50.104 Guidance on defence in depth for cloud-based services, subsection 4.6

Related security controls: AC-2, AC-2(11), AC-3, AC-5, AC-6, AC- 6(5), AC- 6(10), AC-19, AC – 20 (3), IA-2, IA-2(1) IA - 2(2), IA-2(3), IA – 2(11), IA-5(8), SI-4, SI-4(5), SA-4(12), CM-5.