|
The 7 layers of web security that Web-Cow Inc. has implemented in the new eSNACS web portal is an enhanced version that complies with the past recommendations stated in the Auditor General's audit of the Nutrition Cluster Program as part of the Single Audit of the State fiscal year that ended June 30, 2001 and adds a whole new level of sophistication seldom employed in enterprise or government applications.
The NEW security features in eSNACS provide the following: (1) assigns all users unique passwords and challenge question and answers customized solely by the user themselves, (2) creates a user specific virtual workspace, customized specifically for the the user logged into the application, (3) defines and controls access to system menu, application and data, and (4) implements secured, user specific reporting capabilities.
The following is a list of RIDE’s security administration requirements:
- Requires an “Signature of Approval” form for each individual intending to use the eSNACS system, with signature approval of the sponsor administrator for that organization. Only then will a unique user ID, default password and a default question and answer challenge will be assigned (distributed in sealed envelopes).
- Provide ALL users (RIDE staff and users in the field) access to all sponsor/site information using their own user ID/password and unique security roles.
- Requires ALL users (RIDE staff and users in the field) to change default password prior to 1st time entering system.
- Lock user accounts (automatically) if not accessed within 120 days (time frame determined by RIDE administrator).
- Disable user if unable to enter correct user ID/password within 5 attempts.
- Restrict password duplication (RIDE Administrative decision).
- Capture and store computer as well as browser information for overall state system health reporting for each user logging into system regardless of authority. Anonymous storage.
- Captures user actions to provide a management audit trail for several key tables in the system. All fields are updated each time a record is created or modified: These feilds are important indicators to whom made changes.
- Date created,
- Created by ,
- Date last updated,
- Last updated by
|