Secure Configuration Guide
How to securely configure and use your account, projects, and data on the Cancer Genomics Cloud.
The CGC does not provide a customer organizational administrator role. You create and manage your own account — see Sign up for the CGC and Account settings. The highest customer privilege on the platform is project Admin.
- Accounts should belong to named individuals. Do not share your credentials.
- When a member leaves your organization or project, a project administrator should remove them from your projects; users can manage or close their own account from Account settings.
- Administrative functions above the project level (account management and monitoring) are performed by Velsera staff through an internal administrative console and are covered by the platform’s FedRAMP security controls. Contact Support for organizational requests.
-
FedRAMP’s Secure Configuration Guide rules cover several categories of guidance. The following records which elements apply to the CGC and why:Applicability of FedRAMP guide elements
| Guide element | Applicability | Basis |
|---|---|---|
| Top-level administrative accounts (customer organization) | Not applicable | The CGC does not provide a customer organizational administrator role. FedRAMP defines a top-level administrative account as the most privileged account for a customer organization; no such account exists on this platform. Administrative functions above the project level are performed by Velsera under the platform’s FedRAMP security controls. |
| Security settings operable only by top-level administrative accounts | Not applicable | No customer-operable settings of this kind exist on the platform. |
| Centralized (organization-wide) MFA enforcement | Not applicable | Platform-level MFA is not offered on the CGC. Users should use eRA Commons/RAS login for multi-factor authentication. |
| Project and volume permissions, download/export controls, secure defaults, publication, change log | Applicable | Covered in the sections below. |
These determinations are recorded in the platform’s FedRAMP Certification Package.
-
Authentication
- You can log in with an eRA Commons account or a dedicated CGC account — see Sign up for the CGC.
- eRA Commons logins are authenticated by the identity provider, which applies its own multi-factor authentication.
- Platform-level multi-factor authentication is not offered on the CGC. Users should use eRA Commons/RAS login for multi-factor authentication.
- Passwords for CGC accounts are screened against lists of common and breached passwords at sign-up.
-
New project members receive permissions set by the project Admin/Owner. “Read” is the minimal permission granted. When adding a member, Write, Copy and Execute are pre-selected by default — review these and grant only what the member needs before saving.Project permissions
- Grant members only the permissions they need for their role in the project.
- Read shows file names and metadata only. Copy lets a member view file content and download files. Write allows modifying and deleting project files and workflows. Execute runs analyses billed to the project. Admin can change other members’ permissions and add members.
Procedures: Set permissions
-
Data download and export controls
- File downloads are unrestricted by default. The download restriction can only be chosen when a project is created and cannot be reverted — enable it for projects holding controlled-access data. To cover Data Studio as well, also block network access.
- Write access to a volume allows exporting files out of the platform. Grant it only to members authorized to move data off the platform.
-
Secure defaults
| Setting | Default | Operated by |
|---|---|---|
| New project member permissions | Write, Copy, Execute pre-selected when adding a member (“Read” always granted; Admin not granted by default) — set by the project Admin/Owner | Project Admin/Owner |
| File downloads | Unrestricted | Project creator (at creation, irreversible) |
| Platform multi-factor authentication | Not offered; users should use eRA Commons/RAS login for multi-factor authentication | - |
| Password breach screening | Project Admin/Owner | Platform (not configurable) |
-
Reporting a security issue
If you believe you have found a security vulnerability or suspect your account has been compromised, contact Velsera Security immediately at [email protected].
-
Change log
Date Change Until 2026-08-16 Guidance previously distributed across individual documentation pages. 2026-08-16 Revised version; aligned content as per template, determinations and security contact added.
Updated about 2 hours ago
Did this page help you?
