CWS-CARES Security Standard - User Accounts in Prod Sim (CARES 100)

County Security Administrators, System Administrators, Authorized Provisioning Leads, CARES SPOCs, Implementation Coordinators, OCM Coordinators, County Leadership, Tribe Leadership, and State Leadership:

It has come to our attention that generic, test login credentials (e.g., generic training logins, shared Prod Sim, or Training credentials) are being created or requested within the CWS-CARES Prod Sim (CARES 100) environment.

This communication serves as an official notice that the creation, use, or facilitation of unauthorized or generic accounts in any environment with production data is strictly prohibited.

Unlike legacy systems (such as CWS/CMS), CWS-CARES relies strictly on individual identity authentication for user auditing, system logging, and access control. Per the California SAM (State Administrative Manual) and SIMM (Statewide Information Management Manual) policies (SAM 5300-5, SAM 5360, NIST 80-53 Rev5 (IA-2)), every account in Prod Sim (CARES 100) or any technical environment with production data must map directly to an authorized, authentic individual.

County or office administrators must not attempt to bypass local directory integration, change automated email attributes, or establish dummy accounts to shortcut provisioning processes.

Any unauthorized, shared, or generic accounts identified in Prod Sim (CARES 100) or any technical environment with production data will be revoked immediately to protect system security and data integrity.

Required Actions for County Administrators

  1. Immediately discontinue creating or requesting generic or placeholder user profiles within CARES 100 / Prod Sim.
  1. Verify that all active user profiles assigned within your county or administrative scope correspond to valid, single-user identities.
  1. If your county encounters onboarding delays or permission mapping issues, do not implement unauthorized workarounds. Instead, submit a ticket through the standard Tier 2 Help Desk so the project team can assist you directly.

We appreciate your prompt attention to maintaining the security standards of the CWS-CARES environment. Please reach out to the project help desk if you have any questions regarding proper provisioning workflows.

If you have questions, please contact the CWDS Information Security mailbox.

Action Requested:

Please share this communication with all staff who should be aware of these details.  

CWDS Customer Relations

RECENT POST
CATEGORIES
Admin Services
Announcement
Binti County Coordination Meeting
Bulletin
CALS
CARES
CARES-Live
CDT
CWDS
CWS-CARES
CWS-CARES Go-Live
CWS-CARES RFA
CWS/CMS
Case Management
County Advisory Committee (CAC)
County Test Workshop (CTW)
Courts
Customer Relations
Data
Data Management
Data and Interfaces
Education
Eligibility
Eligibility & Foster Care Eligibility Determination (FCED)
Event
Extended User Scenario Testing (EUST)
External System Monthly Meeting
External Systems
Family First Prevention Services Act (FFPSA)
Features & Functionality
Financial Management
Forms & Reports
General
Glossary
Hot Fix
Implementation
Implementation Readiness Meetings
Intake
Interfaces
Interim Release
Jobs
Legacy Systems
Maintenance
Meeting
Milestones
News
Notice
Outage
Pilot
Policy
Portals Migration
Process Information Session (PIS)
Product & Functionality
Product Features
Product Release
Production Simulation
Project Update
Quarterly Update
Regional
Regional User Groups (RUGs)
Release
Report
Research and Design
Resource Family Approval (RFA)
Resource Management
Resources
Roadmap
Service Areas and Milestones
Stakeholder Briefing
State Reporting Systems
Teams and Roles
Testing
Training
Training Information, Planning, and Sharing (TIPS) Meeting
Update
User Access & Permissions
Workshop