GSA / fedramp-automation

FedRAMP Automation
https://www.fedramp.gov/using-the-fedramp-oscal-resources-and-templates/
Other
293 stars 89 forks source link

[Feedback]: component[@type=interconnection]prop[@name="authorized-users"] #577

Open Telos-sa opened 8 months ago

Telos-sa commented 8 months ago

This is a ...

question - need to understand something

This relates to ...

What is your feedback?

The SSP Template refers this element to "Authorized Users/Authentication: List the user roles (e.g., SecOps engineers) authorized to access the service, and provide the authentication method."

image

As shown here.

Please confirm, if this is supposed to reference system-implementation/users/title (which is not required), system-implementation/users/uuid, or system-implementation/users/role-ids/role-id when creating the association.

Specifically, we are looking at the different user types that have access to the interconnection, not the role? Or whichever roles are associated with this user, which can use the interconnect?

Where, exactly?

component[@type=interconnection]prop[@name="authorized-users"]

Other information

No response

Telos-sa commented 8 months ago

specifically, since this is not using the responsible-roles element, need to understand how this information should be correlated back to the user.