Skip to main content

Chronus FedRAMP Secure Configuration Guide

Overview

This guide describes how to securely configure and administer Chronus, and how Chronus aligns with the FedRAMP Recommended Secure Configuration requirements (SCG-CSO and SCG-ENH). It focuses on administrator accounts, the security settings those accounts control, and the practices for keeping the service secure. It supplements and does not replace - the Customer Responsibility Matrix and other materials in the Chronus FedRAMP Certification Package.

1. Requirement coverage

FedRAMP SCG

Description

Relevant Section

SCG-CSO-RSC (required)

Explain how to secure access, configure, operate, decommission of top-level admin accounts

Sections 3, 4, 6, 8

SCG-CSO-RSC (recommended)

Recommend settings relevant to only privileged accounts control

Sections 5, 6, 8

SCG-CSO-AUP (required)

Explain how to obtain and use this guide

Section 8

SCG-CSO-PUB (should)

Make the guide public

Section 9

SCG-CSO-SDF (should)

Ship secure defaults for admin/privileged accounts

Section 6, 7

SCG-ENH-CMP/EXP/API/MRG/VRH (should)

Comparison, export, API, machine-readable guide, versioning

Section 9

2. Terminology and role model

Term

Description

Tier

Organization

Your entire Chronus instance: all programs, users, and organization-wide settings

-

Program (track)

An individual mentoring or connection communities program within your organization

-

Global Administrator

Manages every program, organization-wide settings, users, and integrations; changes can apply to all programs at once

Top-level administrative account

Program (Track) Administrator

Manages a single program, its users, and program-level settings

Privileged account

Member

A standard user with no administrative rights

Standard

3. Authentication: SSO and MFA

  • Single Sign-On (SSO): Chronus supports SSO connected via SAML 2.0 or OIDC to your agency's FedRAMP/IL4-authorized identity provider.

  • Multi-factor authentication (MFA): enforced by your identity provider, using your agency's FedRAMP/IL4-authorized identity provider. Alternatively, agencies can opt for email based MFA as well.

  • Recommended: require SSO for all users so account creation, sign-in, and MFA are all governed by your identity provider.

  • SSO setup: a joint task - agency configures your identity provider, Chronus configures the service side and validates the end-to-end sign-in flow.

4. Secure administration lifecycle for top-level admin accounts

4.1 Secure setup

  • Only an existing Global Administrator can create another Global Administrator (Manage > Enrollment > Administrators > Add administrator)

  • Apply least privilege: grant the fewest administrators possible, and give each the lowest role required for their job (prefer Program Administrator over Global Administrator).

  • Use named, individual accounts - never a shared login. [Not applicable if SSO is enabled]

4.2 Secure configuration

  • An account’s role determines the scope of their administrative access. Assign it deliberately and review it when responsibilities change.

  • Turn on the Section 6 settings that apply to your agency policy (session timeout, account lockout, sign-in banner) and request the Chronus-configured settings you need.

4.3 Secure operation

  • Recurring access reviews: review the administrator list at least quarterly; remove anyone who no longer needs access.

  • Monitoring: review administrator activity and access to mentoring areas (audited access) as part of ongoing oversight.

  • API tokens (if used): store securely; rotate periodically

4.4 Secure decommissioning

Removing a Global Administrator at the organization level does not remove their access to individual programs. To fully revoke access:

  1. Remove Global Administrator access at the organization level.

  2. Remove or deactivate the person in each program they could access.

  3. If they have left the organization, deactivate or remove their user account so they can no longer sign in.

  4. In your identity provider, disable the person so future SSO sign-ins are blocked.

5. Privileged accounts (Program Administrators)

The same lifecycle applies, scoped to a single program: create with least privilege, assign roles deliberately, review access regularly, and remove promptly when no longer needed. Program Administrators cannot change organization-wide settings; those remain with Global Administrators or Chronus.

6. Security settings catalog

Each row lists what the setting does and its security impact, the current default, the recommended value for a Government environment, and who configures it (You = self-service; Chronus = set by Chronus, request via Support).

Setting

What it does / why it matters

Default

Recommended (Government)

Who

Single Sign-On (SSO)

Federates sign-in to your IdP;

SAML SSO

Required for all users

Chronus + Agency IdP

Multi-factor authentication

Second factor verified at your IdP

Enforced at IdP

Required

Agency IdP

Automatic sign-out (inactivity)

Ends idle sessions on unattended devices

120 minutes

15-30 minutes

Agency

Account lockout

Locks account after repeated failed sign-ins

On; (~10 attempts)

On; ~5 attempts

Agency

Sign-in warning banner

Shows system-use / consent-to-monitoring notice

On

On, agency-approved text

Agency

Require sign-in for all pages

Prevents content visible without signing in

On

On

Chronus

Restrict access by IP (web)

Limits access to approved networks

On

Restrict to agency networks

Chronus

Restrict access by IP (API)

Limits programmatic access to approved networks

On

Restrict to agency networks

Chronus

Block rooted/jailbroken devices

Blocks sign-in from tampered devices

On

On

Chronus

Allowed email domains

Restricts which domains can become users

To be setup during onboarding

Agency domain(s) only

Chronus

'Remember me' on sign-in

Keeps a browser signed in longer

Off

Off

Chronus

Password rules (fallback accounts)

Length/complexity/reuse/expiration for non-SSO accounts

SAML SSO

Required for all users

Agency IdP

Data export / reporting access

Controls who can export user/program data

Available to admins

Limit to fewest admins

Agency

Profile visibility

Which profile fields are visible, and to whom

Program-dependent

Only fields the program needs

Agency

7. Secure defaults

Chronus provisions the environment with SSO-based sign-in, MFA enforced at your identity provider, and rooted/jailbroken-device blocking turned on by default (see Section 9). Several other settings ship with permissive defaults (noted in Section 6) so they can be tuned to your agency's policy - review each against the Recommended column at onboarding, and set the self-service items before going live.

8. Other critical compliance components

  • Application runs exclusively in AWS GovCloud (US)

  • FIPS-validated cryptographic endpoints are used.

  • Only FIPS 140-2 validated keys are used for cryptographic purposes

  • Additional DoD-specific hardening applies for DoD customers, including the DISA STIG hardening, and other related IL4 overlays

  • No commercial third-party services such as external web analytics, product-usage tracking, third-party error tracking, and the in-app support chat are enabled

9. Obtaining, using, and improving this guide

  • How to obtain / use (SCG-CSO-AUP): this guide is referenced in the Chronus FedRAMP Certification Package; request the package or this guide from Chronus.

  • Public availability (SCG-CSO-PUB): this guide is published publicly.

10. Enhanced capabilities (SCG-ENH)

SCG-ENH-CMP - Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.

SCG-ENH-EXP - Providers SHOULD offer the capability to export all security settings in a machine-readable format.

SCG-ENH-API - Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.

SCG-ENH-MRG - Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.

SCG-ENH-VRH - Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.

Capability

Status

Note

Compare current settings to defaults (CMP)

Planned

Export security settings, machine-readable (EXP)

Planned

View/adjust security settings via API (API)

Planned

Machine-readable version of this guide (MRG)

Yes

JSON / MD file available

Versioning / release history (VRH)

Yes

See Document details

Did this answer your question?