EDMS, Part IV of the Business Requirement Document
Electronic Document Management System (EDMS), Part III of the Business Requirement Document
|
1
|
|
4
|
EDMS Access
At each stage, the documents are protected to prevent unjustified modifications. Therefore, all the documents are password protected. Passwords have eight characters consisting of upper-and lower-case letters, a numeral and a special character chosen arbitrarily. Besides, Passwords will be updated after every stage so as to provide stage-wise authentication. Any error or wrong password entries lead to an automated logout of up to one hour with an administrator alert being sent after every ten minutes.
A combination of upper and lower-case characters provides for a combination of up to 528 combinations. Adding numbers and special characters provides for added complexity hence difficulties in brute forcing the password. This because the additional characters yield up to 958 combinations therefore, it is almost 120 times more difficult to brute force a password under the suggested policy. Besides, the suggestion is in accordance with Payment Card Data Industry Security Standard (PCD-DISS) section 8.3 volume 3.2 which requires that access to credit card data is authenticated.
PCI-DSS Volume 3.2 of section 2.1 requires that a password is renewed once the system is changed. To comply with the policy, passwords are subject to changes after every two months as stated in the policy recommendation. According to the centre of medical services (CMS) in conjunction with the Human and Health services (HHS) conducted a study which revealed that data breaching whether intentional or even accidental are as a result of previous employees as well as internal hackers. Therefore, training is a necessity for all individuals handling private data as a means of compliance to various policies. Employees are thus trained to be aware of password threats, password protection and also be capable of providing valuable recommendations.
In case a document requires modifications, it is checked out first. The document is thus retrieved from the system and no other user can check it out once more. The desired changes are then made and the document checked in. The document must therefore be checked out before any manipulations are done. However, after checking in, the version number for the document is updated so as to indicate the document has been modified.
References
Cms.gov. (2018). 2008-05-23 - Centres for Medicare & Medicaid Services. [online] Available at: https://www.cms.gov/Newsroom/MediaReleaseDatabase/Fact-sheets/2008-Fact-sheets-items/2008-05-23.html [Accessed 9 Mar. 2018].
securitymetrics.com. (2018). HIPAA Compliant Passwords. [online] Available at: http://blog.securitymetrics.com/2014/05/hipaa-compliant-passwords.html [Accessed 9 Mar. 2018].