open-cmmc-stack/evidence/01_identity_access/evidence.md

16 lines
509 B
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 🔐 Evidence Identity and Access Management
## Purpose
This folder contains evidence showing how user accounts, roles, MFA, and authentication systems are managed via Keycloak and Tailscale.
## Included Artifacts
- Realm export (`keycloak-realm-export.json`)
- Screenshots of MFA policy
- Group-to-role mapping export
- Tailscale ACL and device log
## Review Checklist
- [ ] MFA enforced for all privileged users
- [ ] User roles mapped and validated
- [ ] Keycloak policies match SSP configuration