County Security Administrators, System Administrators, Authorized Provisioning Leads, CARES SPOCs, Implementation Coordinators, OCM Coordinators, County Leadership, Tribe Leadership, and State Leadership:
It has come to our attention that generic, test login credentials (e.g., generic training logins, shared Prod Sim, or Training credentials) are being created or requested within the CWS-CARES Prod Sim (CARES 100) environment.
This communication serves as an official notice that the creation, use, or facilitation of unauthorized or generic accounts in any environment with production data is strictly prohibited.
Unlike legacy systems (such as CWS/CMS), CWS-CARES relies strictly on individual identity authentication for user auditing, system logging, and access control. Per the California SAM (State Administrative Manual) and SIMM (Statewide Information Management Manual) policies (SAM 5300-5, SAM 5360, NIST 80-53 Rev5 (IA-2)), every account in Prod Sim (CARES 100) or any technical environment with production data must map directly to an authorized, authentic individual.
County or office administrators must not attempt to bypass local directory integration, change automated email attributes, or establish dummy accounts to shortcut provisioning processes.
Any unauthorized, shared, or generic accounts identified in Prod Sim (CARES 100) or any technical environment with production data will be revoked immediately to protect system security and data integrity.
Required Actions for County Administrators
- Immediately discontinue creating or requesting generic or placeholder user profiles within CARES 100 / Prod Sim.
- Verify that all active user profiles assigned within your county or administrative scope correspond to valid, single-user identities.
- If your county encounters onboarding delays or permission mapping issues, do not implement unauthorized workarounds. Instead, submit a ticket through the standard Tier 2 Help Desk so the project team can assist you directly.
We appreciate your prompt attention to maintaining the security standards of the CWS-CARES environment. Please reach out to the project help desk if you have any questions regarding proper provisioning workflows.
If you have questions, please contact the CWDS Information Security mailbox.
Action Requested:
Please share this communication with all staff who should be aware of these details.