Laserfiche WebLink
Security Policies and Procedures <br />C. Rules <br />Users are forced to create a new password every 3 months. Users must not write down <br />on paper or store any passwords; they must also never share their passwords with <br />other users. Software is provided to securely store user passwords, with encryption. <br />A maximum 5 attempts will be permitted prior to disabling the account. New <br />passwords must be different from the previous three (3) passwords. Passwords must <br />be changed immediately upon first use of a new ID. Passwords must never be stored or <br />transmitted in clear text. Systems must not echo back the password as it is entered. <br />Passwords must not be retained by any system or application longer than is needed to <br />grant access. Initial passwords must be transmitted separately from the ID. <br />XIII. Authorization and Rights Management <br />A. General Access Roles <br />Access roles are defined as: <br />1. Super Admin Access: Access to all front and backend products as well as <br />product metrics <br />2. Admin Access: Access to all front end products as well as product metrics <br />3. General Access: Access to product metrics <br />4. Low Access: Access to corporate email, sales, and marketing data only <br />Amazon Web Services (AWS) <br />Users who have access to AWS have Super Admin Access. User sessions will expire <br />after one (1) hour of inactivity <br />Cloudant <br />Users who have access to Cloudant have Super Admin Access. User sessions do not <br />automatically time out, the user is required to log out at the end of a session. <br />Github <br />Users who have access to Github have General Access. User sessions do not <br />automatically time out, the user is required to log out at the end of a session. <br />ELK Stack <br />Users who have access to ELK Stack have Admin Access. User sessions do not <br />automatically time out, the user is required to log out at the end of a session. <br />Rev.2015.8.6 <br />29 <br />