professional documents
home
Profile
Upload
docsters
Blogs
Upload
about me
contact me
user photo
Hassan Maher
IT Governance
CMDB Manager
Al Rajhi Bank
An accomplished Information Services professional with extensive experience in bringing cutting-edge technology to corporate clients. Proven ability to conduct accurate needs analysis, Root Cause Analysis, solve problems, assess t...
submit clear
Word Document

Security Requirements center doc

ABC-TT-01 VersionV 1.0 PageV 1V2 Confidential V All rights reserved. Passing on and copying of this document, use and communication of its contents not permitted without written authorization. Security Requirements The use of security mechanisms is critical for the reduction of possible falsification or theft of information. To ensure the security of these modules Vfocusing here on the application, application equipment and software needsV and its information, the following shall be providedV Require password entry to gain initial access to the system. Require password entry immediately before non-standard high-level activity. Not display passwords on the screen during entry. Allow individual user access rights to be tailored to specific tasks or task groups. Validate passwords to prevent use of trivial or insecure passwords. Support an automatic log-off after a certain time period, e.g. 2 minutes or system administrator configurable time period. Enforce password expiry after a specified time span, and prevent reuus of passwords. Store passwords in an encrypted form, separately from the main database. Disable or disconnect terminals which have been inactive for a specified period of time. Provide the necessary technical specifications for recognition of passwords, digital signatures, fingerprints and other personal recognition methods to prove the integrity and authenticity of data and protect against forgery. A log file shall be kept with the usersV actions recorded by module functionality. All users of a module shall have a unique username and password. The users shall be forced to change their password on regular basis Ve.g. every V0 daysV. Reporting and registering in a log file any attempts for breaching access codes. Each module shall provide a maximum number of login attempts in case of a wrong password. When that maximum number is reached the user account will be temporarily disabled until the problem is located and the proper measures are taken. Include the necessary mechanisms for safeguarding the continuous availability, confidentiality and integrity of the data stored in the system. Ensure that before connecting to the system the user's identity, authority level and security profile are verified. ABC-TT-01 VersionV 1.0 PageV 2V2 Confidential V All rights reserved. Passing on and copying of this document, use and communication of its contents not permitted without written authorization. Be capable of preventing the use of unique identification numbers for any other purpose other than the provision of healthcare services. Be able to detect and report any breaches of security. Allow the application of consent by multiple authorized users for the opening and processing of certain files containing identification fields and sensitive personal data that can possibly be matched with external files. Support a single password to access different modules and levels of data. Vse audit trails to track all activity of data editing and editing persons at all times in order to minimize the possibility of undetectable alteration of data. Support security mechanisms and a list of European and international standards in every module
rate this doc
email this doc
embed this doc
add to folder
digg reddit stumble delicious
flag this doc
471
67
7(1)
0
12/1/2007
English
search termpage on Googletimes searched
Preview

DEA Security Requirements for Personnel Security

DOJ 6/4/2008 | 29 | 1 | 0 | legal
Preview

Security Requirements FY ppt - Security

FHA 6/19/2008 | 26 | 3 | 0 | legal
Preview

Sample of Acceptable Security Requirements Documents

SSA 6/19/2008 | 18 | 5 | 0 | legal
Preview

Social Security Registration Requirements

ronaldmiller 5/13/2008 | 69 | 0 | 0 | legal
Preview

Safeguards and Security Requirements for Work at Y

EIA 5/30/2008 | 16 | 1 | 0 | legal
Preview

PHYSICAL INVENTORY REQUIREMENTS FOR SECURITY ITEMS

CCO 6/18/2008 | 19 | 1 | 0 | legal
Preview

State Security Freeze Requirements and Fees

anonymous 11/7/2007 | 245 | 5 | 0 | financial
Preview

filemaker security requirements white paper

tlindeman 4/4/2008 | 197 | 1 | 0 | technology
Preview

Meeting the PCI Application Security Requirements

LisaB1982 4/6/2008 | 110 | 5 | 0 | technology
Preview

DEA Security Requirements for Personnel Security - Acquisitions & Contracts

DOJ 6/17/2008 | 9 | 0 | 0 | legal
Preview

Security Requirements FY ppt - Security

TDdocs 6/26/2008 | 17 | 1 | 0 | legal
Preview

IT Security-Risk Mitigation Service Level Requirements Worksheet

user002 2/5/2008 | 130 | 22 | 0 | business
Preview

Bachelor of Science in Security Management - Degree Requirements for Port Security Specialists

CoastGuard 5/30/2008 | 8 | 0 | 0 | legal
Preview

Undergraduate Certificate in Homeland Security - Degree Requirements for Port Security Specialists

CoastGuard 5/30/2008 | 5 | 0 | 0 | legal
Preview

Professional Certificate in Homeland Security - Degree Requirements for Port Security Specialists

CoastGuard 5/30/2008 | 4 | 0 | 0 | legal
Preview

Evaluation Criteria

hassanmaher 12/1/2007 | 602 | 69 | 0 | business
 
review this doc