Skip to content

No authentication coverage report for assessment and insurance responses #178

Description

@Bccorb

Part of #155. Session 7. Depends on #177 and #165.

Problem

Nothing in the product answers the question an agency actually needs answered:
how much of our staff is on phishing-resistant authentication, and is that number
going up.

The data exists across users, credentials and auth_events, but there is no
report that assembles it.

Why it matters

This is the artifact that converts a one-off Stage 1 assessment into a renewing
engagement, and it maps directly onto three commitments:

  • Phase 5 of the migration runbook promises "authentication coverage figures for the
    audit response" and an "authentication section drafted for the cyber insurance
    renewal questionnaire" in the annual evidence package
  • Maryland jurisdictions self-assess against DoIT's NIST CSF-based Local Cyber
    Assessment Tool. Its identity and access control items are exactly what this
    report answers
  • Where grant funding was used, the runbook promises "the before and after picture
    the grant administrator will ask for"

What to do

Acceptance

  • An operator can produce coverage figures for a period without writing SQL
  • The report states both actual coverage and enforced policy
  • Output is suitable for pasting into an assessment response

Freeze status

Exception 4. This is the deliverable the engagement model sells, so it should not be
built before a customer asks, but it should be specced now.

Ripple

New route, so seamless-auth-server needs passthrough in all three adapter
allowlists. The admin dashboard is the natural place to surface it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions