CDP Control ID:35948455 Category: Least Privileged Access Frequency: Annually Owner: h.noerenberg Parent:#1
Requirement & Guidance
Least Privileged Access Requirement: Provide access to individuals that is appropriate for their role and responsibilities, using the concept of Least Privileged Access, meaning individuals are only granted access to those resources and systems that are required to enable their delivery role. To give proper access it may be appropriate to create a separate new user ID rather than extending access rights of an existing ID. Guidance: Confirm Role Based Access Control is maintained in all systems and applications to ensure that no resource has been assigned additional privileges than required for the services. Maintain and review the access levels of resources for appropriateness (right people having right access to right systems) and record any changes for tracking and auditing purposes. Additional information can be found on CDP website Least Privileged Access
**CDP Control ID:** `35948455`
**Category:** Least Privileged Access
**Frequency:** Annually
**Owner:** h.noerenberg
**Parent:** #1
## Requirement & Guidance
Least Privileged Access Requirement: Provide access to individuals that is appropriate for their role and responsibilities, using the concept of Least Privileged Access, meaning individuals are only granted access to those resources and systems that are required to enable their delivery role. To give proper access it may be appropriate to create a separate new user ID rather than extending access rights of an existing ID. Guidance: Confirm Role Based Access Control is maintained in all systems and applications to ensure that no resource has been assigned additional privileges than required for the services. Maintain and review the access levels of resources for appropriateness (right people having right access to right systems) and record any changes for tracking and auditing purposes. Additional information can be found on CDP website Least Privileged Access
EAPPS-Mapping:3.2.2.3.11 / Access Control Standard Status:✅OK (laut docs/acn-security-compliance-status.md)
Zusammenfassung
Zugriff wird strikt rollenbasiert erteilt. Jede Rolle hat defaultPermissions: PermissionKey[]; einzelne User können zusätzlich individuelle Overrides erhalten.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
CDP Control ID:
35948455Category: Least Privileged Access
Frequency: Annually
Owner: h.noerenberg
Parent: #1
Requirement & Guidance
Least Privileged Access Requirement: Provide access to individuals that is appropriate for their role and responsibilities, using the concept of Least Privileged Access, meaning individuals are only granted access to those resources and systems that are required to enable their delivery role. To give proper access it may be appropriate to create a separate new user ID rather than extending access rights of an existing ID. Guidance: Confirm Role Based Access Control is maintained in all systems and applications to ensure that no resource has been assigned additional privileges than required for the services. Maintain and review the access levels of resources for appropriateness (right people having right access to right systems) and record any changes for tracking and auditing purposes. Additional information can be found on CDP website Least Privileged Access
CapaKraken Action Plan — 35948455 Role-Based Access (Least Privilege)
Scope: Role-Based Access Control, individuell je Rolle.
Aktueller Stand:
docs/acn-security-compliance-status.md3.2.2.3.11 OK — RBAC mitadminProcedureRoleenum +UserRolejoin table (packages/db/prisma/schema.prisma)Todos:
adminProcedure/protectedProcedureauf Least Privilege prüfendocs/rbac-matrix.md(neu) + Review-LogDateien:
packages/api/src/router/trpc.ts— Procedure-Levelspackages/db/prisma/schema.prisma— Role enumCapaKraken Compliance-Status
EAPPS-Mapping:
3.2.2.3.11 / Access Control StandardStatus: ✅ OK (laut
docs/acn-security-compliance-status.md)Zusammenfassung
Zugriff wird strikt rollenbasiert erteilt. Jede Rolle hat
defaultPermissions: PermissionKey[]; einzelne User können zusätzlich individuelle Overrides erhalten.Nachweis
SystemRoleConfigmitdefaultPermissions Json @db.JsonB—packages/db/prisma/schema.prismaUser.permissionOverridesfür Feingranularität —packages/db/prisma/schema.prismaapps/web/src/app/(app)/adminEntscheidung: Control ist nachweislich erfüllt → Ticket wird geschlossen.