FedRAMP Security Admin Guide

FedRAMP Security Admin Guide

Administrative and privileged accounts

Relevant requirements: FRR-RSC-01, FRR-RSC-02, FRR-RSC-03, FRR-RSC-06

Hypercell uses permission groups to define general user authorization. These permission groups contain sets of permissions that allow you to limit user access to application functionality based on their use cases and requirements.
For more information on individual permissions and those assigned to specific permission groups by default, see Permission Groups.

System Admin

Relevant requirements: FRR-RSC-01
Top-level administrative account holders are users who belong to the pre-defined System Admin permission group. This group is the most privileged default permission group, with access to all permissions and data within the Hypercell instance.

Only users within the System Admin permission group can carry out the following:

Administration

Flows

Library

Submissions

User Management

Business Admin

Relevant requirements: FRR-RSC-03
User accounts within the pre-defined Business Admin permission group are primarily responsible for managing layouts. They are also able to view system reporting, along with the management of submissions. As a result, they are more privileged than other permission groups (but not more than those within the System Admin permission group).

Ignoring those within the System Admin permission group, only users within the Business Admin permission group can carry out the following:

Administration

Flows

Library

Reporting

Submissions

User Management

Initial Hypercell configuration and maintenance

Relevant requirements: FRR-RSC-01, FRR-RSC-02
To follow security best practices, after initial configuration has completed any accounts that are part of the System Admin or Business Admin permission groups should be assigned to a less privileged group, unless they are owned by users who require their elevated permissions as part of their expected work.

Configuring administrative and privileged accounts

Relevant requirements: FRR-RSC-01, FRR-RSC-02, FRR-RSC-03
In FedRAMP and other instances where an external authentication provider is configured, user management is carried out through that external provider. Hypercell maps permission groups to groups within the external provider’s system. As such, the assignment of users to groups with privileged permissions is handled through the external authentication provider.

Importing and exporting system settings and permissions

Requirements addressed: FRR-RSC-06
The system allows you to import and export the system settings of your choosing. This includes settings such as session duration or PII-data-retention periods.
To learn more about importing and exporting system settings, see Importing & Exporting Settings.
Similarly, you can import and export any or all of the permission groups in your instance. For more information, see Managing Permission Groups.
Settings and permissions are exported in JSON format.

Comparing your permissions to recommended secure defaults

Requirements addressed: FRR-RSC-05, FRR-RSC-08
You cannot change the permissions for any of the pre-defined permission groups, including System Admins and Business Admins. However, you can create your own permission groups to meet the needs of your organization.
When you create a custom permission group, you may want to compare its access permissions to the secure default permissions in the System Admin or Business Admin permission group.
It is recommended to follow the principle of least privilege, using the pre-defined permission groups or creating custom permission groups that grant your users the bare minimum access required to carry out their expected work in the application.

Editing system settings and permissions via API

Requirements addressed: FRR-RSC-07
It is not currently possible to edit system settings or permissions via API.
To learn more about our API’s capabilities, see our API documentation (opens in new tab).

Changes to settings and permissions across versions

Requirements addressed: FRR-RSC-10
We describe changes to our system settings and pre-defined permission groups, along with other product updates, in our release notes. Release notes are published for each patch, minor, and major version.