Account Management ¶
1. Purpose and Scope ¶
- This section defines the requirements for system account creation, usage, management, and removal to ensure access is granted based on business needs, the principle of least privilege, and security and compliance requirements.
- Support STIG compliance with AC-02-00.
2. System Account Types ¶
2.1 Permitted system account ¶
- Individual accounts
- System accounts
- Service accounts
2.2 Restricted or prohibited account types ¶
Due to increased security risks, the following account types are restricted or prohibited
- Shared accounts
- Group accounts
- Anonymous accounts
- Guest accounts
3. Roles and Responsibilities ¶
3.1 Account Managers ¶
Account managers are responsible for creating, modifying, disabling, and removing accounts, as well as monitoring account usage. They must ensure that all account activities are authorized, documented, and aligned with approved business requirements, the principle of least privilege, and applicable security and compliance policies.
You can carry out the above operations on this page. User Opeartion
All user information is stored in the mct_member table in PostgreSQL.
3.2 Approval Roles ¶
Account creation does not currently require an approval process. Account information is synchronized with Cisco accounts. Once a user has a Cisco account, they can access MCT applications with View-Only permissions. Privileged access still requires approval in accordance with established access control procedures.
There are four types of privileges: Administrator,MCT Service Admin,MCT Service Owner,View Only.
4. Access Authorization and Privileges ¶
System access is granted only to authorized users and configured based on assigned roles and responsibilities. Access rights must align with approved business requirements and follow the principle of least privilege. Access permissions shall be reviewed periodically and adjusted promptly to reflect changes in roles, responsibilities, or employment status.
5. Account Lifecycle Management ¶
Account management covers the following lifecycle stages:
- Creation and activation: Accounts are created and activated based on approved requests and business requirements.
- Modification: Account details and access privileges are updated in accordance with changes in roles or responsibilities.
- Disabling and removal: Accounts that are no longer required are promptly disabled or removed to prevent unauthorized access.
All account management activities must be performed in accordance with organizational policies and procedures and comply with applicable security and compliance requirements.
6. Account Monitoring and Review ¶
- Monitor account usage on an ongoing basis to detect anomalous or unauthorized behavior and respond in a timely manner.
This page activity log allows you to view the user’s activity. Such as Add, Update, Delete, Failover,Maintain,Unmaintain and other related actions.
7. Account Change ¶
Account administrators are authorized to disable, delete, or modify user accounts.
Account changes include the following: - Accounts are no longer required for business purposes;
- Users are terminated, transferred, or otherwise change employment status;
- Access requirements or need-to-know levels change.
Such changes enable timely review, modification, or revocation of access to maintain security, compliance, and adherence to the principle of least privilege.
Account management processes are aligned with onboarding, termination processes to ensure timely provisioning, modification, and revocation of access. This alignment helps ensure that access rights accurately reflect users’ current roles and responsibilities and remain consistent with business, security, and compliance requirements.
Reference ¶
- Current authorized system users:User List
- Activity-Log
- How to access MCT