Skip to main content

Password and Security Settings

The Password and Security Settings infeature OPSCOM provideprovides administrators with critical tools to enforce robust password policies and manage login security for all backend administrative accounts. ProperlyIts configuringprimary these settingspurpose is essentialto for protectingprotect sensitive system data, preventingprevent unauthorized access, and complyingensure organizational compliance with organizationalmodern security standards. This article is intended for OPS-COM administrators responsible for managing backend system configuration and access security.

Setup and Configuration

This feature requires high-level administrative access to view and manage global security protocols.

SecurityAdmin Side: Administrators must have the appropriate system role permissions enabled to access the centralized system settings are managed within the System Settings area of OPSCOM.menu.

  1. Hover over System Configuration,Configuration and click System Settings.

  2. Click Security. Theto Manageopen Systemthe Settingsmanagement window willand open, displayingview all available security configurations.

User Side: This feature dictates backend administrative security and does not directly configure the end-user parking portal login policies.

Using this Feature

TheAdministrators Securitycan componentuse withinthe Systemconfiguration Settings allows administratorswindow to configuredefine various aspects of password managementmanagement, strength requirements, and automated account lockout policies.

Password Security Settings

  • Salted Password HashingHashing::

    • Purpose: This setting addsAdds an essential layer of security toby storedirreversibly passwords.converting Hashing is a one-way, irreversible process that converts a user's passwordpasswords into a unique, short hash value.values "Salting" introduceswith a randomrandomized string"salt" intostring. thisThis process, ensuringensures that even if two users haveshare the same password, their stored hash values willremain becompletely different. ThisIt prevents "lookup" (reverse engineering) of the original password,engineering, meaning forgotten passwords must be reset,reset notrather than retrieved. This significantly limits an administrator's ability to view employee passwords and closes a critical security vulnerability.

Note: Once Hash and Salt is enabled, it should not be turned off.

  • Require Password UpdateUpdate::

      Forces
    • Purpose: When activated, this setting forces usersadministrators to change their passwords upon their next successful login.
    • UseThis Case:is Idealideal for ensuring compliance with regular password changes or after a manual password reset by an administrator.
    reset.

  • Toggle Password ExpiryExpiry::

    • Purpose: By default, passwords in OPSCOM do not expire. For enhanced security, it is best practice to mandateMandates regular password changes. ThisWhen settingenabled, enablesenter a numerical value into the use of password expiry.
    • Configuration: Toggle this setting On.
    • Password Expiry in days: Enterfield to define the numberexact lifecycle of days after which an administrator'sactive password will expire, aligning with your organization's security policy (e.g., 90 days).

  • Enable Password HistoryHistory::

    • Purpose: When toggled On, OPSCOM will rememberRemembers passwords previously used by an administrator.administrator The system will thento prevent immediate reuse. When enabled, set the reuse of those passwords for a specified period.
    • Configuration: Set How long to remember old passwords field (in days) to define the durationrestriction for which old passwords are not allowed to be reused.
    duration.

Password Strength Requirements

These settings allow you to enforce complexity rules for all new administrator passwords.passwords:

  • Minimum Password LengthLength:: Sets the absolute minimum number of characters required for a valid password.

  • Enable password strength requirementsrequirements:: Toggles specific complexity rules on or offoff. theWhen followingenabled, specificyou complexitycan requirements:set

      a
    • minimum required character count for Numerical Characters:, Sets the minimum number of numbers required in the password.
    • Lower Case Characters:, Sets the minimum number of lowercase characters required in the password.
    • Upper Case Characters:, Setsand the minimum number of uppercase characters required in the password.
    • Non-Alpha Numeric: Sets the minimum number of non-alphanumeric (special) characters required in the password (e.g., !, &, #, etc.)#).

Admin Account Lockout Settings

These settings provide an additionalautomated layer of security by locking an administrator out of their account after repeated incorrect password attempts.attempts:

  • Enable Admin LockoutsLockouts:: Toggles the automated account lockout feature on or offoff.

    the account lockout feature.
  • Lockout after X AttemptsAttempts:: Sets the numberthreshold offor failed login attempts with an incorrect password before the system willactively locklocks out the administrator.

  • Login attempt timeframetimeframe:: Sets the timeframe (in minutes) during which incorrect login attempts are counted. For example, if an administrator fails 3 times within a 5-minute period, their account will be locked out.

  • Lock the admin out for X minutesminutes:: Sets the duration (in minutes) that the administrator's account will remain locked. For example, setting it to 120 minutes would meanmeans the administrator is completely locked out for 2 hours before another login attempt is permitted.

Several major security settings (such as Salted Password Hashing, password expiry, and lockouts) are visible to administrators but can only be changed by the OPS-COM Team. For modifications to these restricted, read-only settings, please contact support@ops-com.com.


Best Practices &and Considerations

  • RobustEnable Securitysalted Policypassword hashing:: Ensure Salted Password Hashing is permanently enabled for maximum password security. Once enabled, this setting should never be turned off, as doing so reopens a critical security vulnerability and allows administrators to view raw employee passwords.

  • Maintain a robust security policy: Always implement a robustcomprehensive security policy that combines strong password requirementsrequirements, (length,mandatory complexity),expiry password expiry,limits, and lockout mechanisms.

  • EnableEnforce Hashing: Ensure Salted Password Hashing is always enabled for maximumregular password security.

  • expiry:
  • Regular Password Expiry: Enforce regular password expiry intervals (e.g., every 90 days) to mitigate the risk of compromised credentials. Stale passwords are a primary vector for unauthorized access.

  • MeaningfulConfigure Lockoutmeaningful Settingslockout settings:: Configure lockout settings to balance strict security with user convenience. TooOverly aggressive settings can lead to frequentconstant lockouts,lockouts and administrative overhead, while too lenient settings canfail beto aprevent securityactive risk.brute-force attacks.

  • CommunicationCommunicate policies to staff:: Inform administrators about the security policies in place, including password strength requirements, expiry rules,requirements and lockout procedures. ThisClear communication helps themstaff comply and understand exactly why they might be temporarily locked out.

  • out
  • Admins can see, only OPSCOM Team can change: Several security settings (e.g., Hash and Salt, Require Password Update, Toggle Password Expiry, Enable Password History, Enable password strength requirements, Enable Admin Lockouts) are visible to administrators but can only be changed byof the OPSCOMsystem.

    Team. For modifications to these specific settings, contact OPSCOM Support.