Password and Security Settings
The Password and Security Settings infeature OPSCOM provideprovides administrators with critical tools to enforce robust password policies and manage login security for all backend administrative accounts. ProperlyIts configuringprimary these settingspurpose is essentialto for protectingprotect sensitive system data, preventingprevent unauthorized access, and complyingensure organizational compliance with organizationalmodern security standards. This article is intended for OPS-COM administrators responsible for managing backend system configuration and access security.
Setup and Configuration
This feature requires high-level administrative access to view and manage global security protocols.
SecurityAdmin Side: Administrators must have the appropriate system role permissions enabled to access the centralized system settings are managed within the System Settings area of OPSCOM.menu.
-
Hover over System
Configuration,Configuration and click System Settings. -
Click Security
.ThetoManageopenSystemtheSettingsmanagement windowwillandopen, displayingview all available security configurations.
User Side: This feature dictates backend administrative security and does not directly configure the end-user parking portal login policies.
Using this Feature
TheAdministrators Securitycan componentuse withinthe Systemconfiguration Settings allows administratorswindow to configuredefine various aspects of password managementmanagement, strength requirements, and automated account lockout policies.
Password Security Settings
-
Salted Password
HashingHashing::Purpose: This setting addsAdds an essential layer of securitytobystoredirreversiblypasswords.convertingHashing is a one-way, irreversible process that converts a user's passwordpasswords intoaunique, short hashvalue.values"Salting" introduceswith arandomrandomizedstring"salt"intostring.thisThisprocess, ensuringensures that even if two usershaveshare the same password, their stored hash valueswillremainbecompletely different.ThisIt prevents"lookup" (reverseengineering) of the original password,engineering, meaning forgotten passwords must bereset,resetnotrather than retrieved.This significantly limits an administrator's ability to view employee passwords and closes a critical security vulnerability.
Note: Once Hash and Salt is enabled, it should not be turned off.
-
Require Password
UpdateUpdate::- Forces
Purpose: When activated, this setting forces usersadministrators to change their passwords upon their next successful login.UseThisCase:isIdealideal for ensuring compliancewith regular password changes orafter a manual passwordreset by an administrator.
-
Toggle Password
ExpiryExpiry::Purpose: By default, passwords in OPSCOM do not expire. For enhanced security, it is best practice to mandateMandates regular password changes.ThisWhensettingenabled,enablesenter a numerical value into theuse of password expiry.Configuration: Toggle this settingOn.- Password Expiry in days
:Enterfield to define thenumberexact lifecycle ofdays after whichanadministrator'sactive passwordwill expire, aligning with your organization's security policy(e.g., 90 days).
-
Enable Password
HistoryHistory::Purpose: When toggledOn, OPSCOM will rememberRemembers passwords previously used by anadministrator.administratorThe system will thento prevent immediate reuse. When enabled, set thereuse of those passwords for a specified period.Configuration: SetHow long to remember old passwords field (in days) to define thedurationrestrictionfor which old passwords are not allowed to be reused.
Password Strength Requirements
These settings allow you to enforce complexity rules for all new administrator passwords.passwords:
-
Minimum Password
LengthLength::Sets the absolute minimum number of characters required for a valid password. -
Enable password strength
requirementsrequirements::Toggles specific complexity rules on oroffoff.theWhenfollowingenabled,specificyoucomplexitycanrequirements:set- a
- minimum required character count for Numerical Characters
:,Sets the minimum number of numbers required in the password. - Lower Case Characters
:,Sets the minimum number of lowercase characters required in the password. - Upper Case Characters
:,Setsandthe minimum number of uppercase characters required in the password. - Non-Alpha Numeric
: Sets the minimum number of non-alphanumeric (special)charactersrequired in the password(e.g.,!, &,#,etc.)#).
- minimum required character count for Numerical Characters
Admin Account Lockout Settings
These settings provide an additionalautomated layer of security by locking an administrator out of their account after repeated incorrect password attempts.attempts:
-
Enable Admin
LockoutsLockouts::Toggles the automated account lockout feature on oroffoff.the account lockout feature. -
Lockout after X
AttemptsAttempts::Sets thenumberthresholdoffor failed login attempts with an incorrect password before the systemwillactivelylocklocks out the administrator. -
Login attempt
timeframetimeframe::Sets the timeframe (in minutes) during which incorrect login attempts are counted. For example, if an administrator fails 3 times within a 5-minute period, their account will be locked out. -
Lock the admin out for X
minutesminutes::Sets the duration (in minutes) that the administrator's account will remain locked. For example, setting it to120 minuteswould meanmeans the administrator is completely locked out for 2 hours before another login attempt is permitted.
Several major security settings (such as Salted Password Hashing, password expiry, and lockouts) are visible to administrators but can only be changed by the OPS-COM Team. For modifications to these restricted, read-only settings, please contact support@ops-com.com.
Best Practices &and Considerations
-
RobustEnableSecuritysaltedPolicypassword hashing::Ensure Salted Password Hashing is permanently enabled for maximum password security. Once enabled, this setting should never be turned off, as doing so reopens a critical security vulnerability and allows administrators to view raw employee passwords. -
Maintain a robust security policy: Always implement a
robustcomprehensive security policy that combines strong passwordrequirementsrequirements,(length,mandatorycomplexity),expirypassword expiry,limits, and lockout mechanisms. -
EnableEnforceHashing: EnsureSalted Password Hashingis always enabled for maximumregular passwordsecurity.expiry: Regular Password Expiry:Enforce regular password expiry intervals (e.g., every 90 days) to mitigate the risk of compromised credentials. Stale passwords are a primary vector for unauthorized access.-
MeaningfulConfigureLockoutmeaningfulSettingslockout settings::Configure lockout settings to balance strict security with user convenience.TooOverly aggressive settings can lead tofrequentconstantlockouts,lockouts and administrative overhead, whiletoolenient settingscanfailbetoapreventsecurityactiverisk.brute-force attacks. -
CommunicationCommunicate policies to staff::Inform administrators about the security policies in place, including password strengthrequirements, expiry rules,requirements and lockout procedures.ThisClear communication helpsthemstaff comply and understand exactly why they might be temporarily lockedout.out Admins can see, only OPSCOM Team can change: Several security settings (e.g.,Hash and Salt,Require Password Update,Toggle Password Expiry,Enable Password History,Enable password strength requirements,Enable Admin Lockouts) are visible to administrators but can only be changed byof theOPSCOMsystem.Team. For modifications to these specific settings, contactOPSCOM Support.