Overview
This guide describes how to securely configure and administer Chronus, and how Chronus aligns with the FedRAMP Recommended Secure Configuration requirements (SCG-CSO and SCG-ENH). It focuses on administrator accounts, the security settings those accounts control, and the practices for keeping the service secure. It supplements and does not replace - the Customer Responsibility Matrix and other materials in the Chronus FedRAMP Certification Package.
1. Requirement coverage
FedRAMP SCG | Description | Relevant Section |
SCG-CSO-RSC (required) | Explain how to secure access, configure, operate, decommission of top-level admin accounts | Sections 3, 4, 6, 8 |
SCG-CSO-RSC (recommended) | Recommend settings relevant to only privileged accounts control | Sections 5, 6, 8 |
SCG-CSO-AUP (required) | Explain how to obtain and use this guide | Section 8 |
SCG-CSO-PUB (should) | Make the guide public | Section 9 |
SCG-CSO-SDF (should) | Ship secure defaults for admin/privileged accounts | Section 6, 7 |
SCG-ENH-CMP/EXP/API/MRG/VRH (should) | Comparison, export, API, machine-readable guide, versioning | Section 9 |
2. Terminology and role model
Term | Description | Tier |
Organization | Your entire Chronus instance: all programs, users, and organization-wide settings | - |
Program (track) | An individual mentoring or connection communities program within your organization | - |
Global Administrator | Manages every program, organization-wide settings, users, and integrations; changes can apply to all programs at once | Top-level administrative account |
Program (Track) Administrator | Manages a single program, its users, and program-level settings | Privileged account |
Member | A standard user with no administrative rights | Standard |
3. Authentication: SSO and MFA
Single Sign-On (SSO): Chronus supports SSO connected via SAML 2.0 or OIDC to your agency's FedRAMP/IL4-authorized identity provider.
Multi-factor authentication (MFA): enforced by your identity provider, using your agency's FedRAMP/IL4-authorized identity provider. Alternatively, agencies can opt for email based MFA as well.
Recommended: require SSO for all users so account creation, sign-in, and MFA are all governed by your identity provider.
SSO setup: a joint task - agency configures your identity provider, Chronus configures the service side and validates the end-to-end sign-in flow.
4. Secure administration lifecycle for top-level admin accounts
4.1 Secure setup
Only an existing Global Administrator can create another Global Administrator (Manage > Enrollment > Administrators > Add administrator)
Apply least privilege: grant the fewest administrators possible, and give each the lowest role required for their job (prefer Program Administrator over Global Administrator).
Use named, individual accounts - never a shared login. [Not applicable if SSO is enabled]
4.2 Secure configuration
An account’s role determines the scope of their administrative access. Assign it deliberately and review it when responsibilities change.
Turn on the Section 6 settings that apply to your agency policy (session timeout, account lockout, sign-in banner) and request the Chronus-configured settings you need.
4.3 Secure operation
Recurring access reviews: review the administrator list at least quarterly; remove anyone who no longer needs access.
Monitoring: review administrator activity and access to mentoring areas (audited access) as part of ongoing oversight.
API tokens (if used): store securely; rotate periodically
4.4 Secure decommissioning
Removing a Global Administrator at the organization level does not remove their access to individual programs. To fully revoke access:
Remove Global Administrator access at the organization level.
Remove or deactivate the person in each program they could access.
If they have left the organization, deactivate or remove their user account so they can no longer sign in.
In your identity provider, disable the person so future SSO sign-ins are blocked.
5. Privileged accounts (Program Administrators)
The same lifecycle applies, scoped to a single program: create with least privilege, assign roles deliberately, review access regularly, and remove promptly when no longer needed. Program Administrators cannot change organization-wide settings; those remain with Global Administrators or Chronus.
6. Security settings catalog
Each row lists what the setting does and its security impact, the current default, the recommended value for a Government environment, and who configures it (You = self-service; Chronus = set by Chronus, request via Support).
Setting | What it does / why it matters | Default | Recommended (Government) | Who |
Single Sign-On (SSO) | Federates sign-in to your IdP; | SAML SSO | Required for all users | Chronus + Agency IdP |
Multi-factor authentication | Second factor verified at your IdP | Enforced at IdP | Required | Agency IdP |
Automatic sign-out (inactivity) | Ends idle sessions on unattended devices | 120 minutes | 15-30 minutes | Agency |
Account lockout | Locks account after repeated failed sign-ins | On; (~10 attempts) | On; ~5 attempts | Agency |
Sign-in warning banner | Shows system-use / consent-to-monitoring notice | On | On, agency-approved text | Agency |
Require sign-in for all pages | Prevents content visible without signing in | On | On | Chronus |
Restrict access by IP (web) | Limits access to approved networks | On | Restrict to agency networks | Chronus |
Restrict access by IP (API) | Limits programmatic access to approved networks | On | Restrict to agency networks | Chronus |
Block rooted/jailbroken devices | Blocks sign-in from tampered devices | On | On | Chronus |
Allowed email domains | Restricts which domains can become users | To be setup during onboarding | Agency domain(s) only | Chronus |
'Remember me' on sign-in | Keeps a browser signed in longer | Off | Off | Chronus |
Password rules (fallback accounts) | Length/complexity/reuse/expiration for non-SSO accounts | SAML SSO | Required for all users | Agency IdP |
Data export / reporting access | Controls who can export user/program data | Available to admins | Limit to fewest admins | Agency |
Profile visibility | Which profile fields are visible, and to whom | Program-dependent | Only fields the program needs | Agency |
7. Secure defaults
Chronus provisions the environment with SSO-based sign-in, MFA enforced at your identity provider, and rooted/jailbroken-device blocking turned on by default (see Section 9). Several other settings ship with permissive defaults (noted in Section 6) so they can be tuned to your agency's policy - review each against the Recommended column at onboarding, and set the self-service items before going live.
8. Other critical compliance components
Application runs exclusively in AWS GovCloud (US)
FIPS-validated cryptographic endpoints are used.
Only FIPS 140-2 validated keys are used for cryptographic purposes
Additional DoD-specific hardening applies for DoD customers, including the DISA STIG hardening, and other related IL4 overlays
No commercial third-party services such as external web analytics, product-usage tracking, third-party error tracking, and the in-app support chat are enabled
9. Obtaining, using, and improving this guide
How to obtain / use (SCG-CSO-AUP): this guide is referenced in the Chronus FedRAMP Certification Package; request the package or this guide from Chronus.
Public availability (SCG-CSO-PUB): this guide is published publicly.
10. Enhanced capabilities (SCG-ENH)
SCG-ENH-CMP - Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.
SCG-ENH-EXP - Providers SHOULD offer the capability to export all security settings in a machine-readable format.
SCG-ENH-API - Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.
SCG-ENH-MRG - Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.
SCG-ENH-VRH - Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.
Capability | Status | Note |
Compare current settings to defaults (CMP) | Planned |
|
Export security settings, machine-readable (EXP) | Planned |
|
View/adjust security settings via API (API) | Planned |
|
Machine-readable version of this guide (MRG) | Yes | JSON / MD file available |
Versioning / release history (VRH) | Yes | See Document details |
