|
|
||||||||||||||||
|
|
|
|
|
|||||||||||||
|
|
Centers for Disease Control and Prevention Division of Cancer Prevention and Control 4770 Buford Hwy, NE MS K-64 Atlanta, GA 30341-3717 Call: 1 (800) CDC-INFO TTY: 1 (888) 232-6348 FAX: (770) 488-4760 E-mail: cdcinfo@cdc.gov |
|
|
|
Security Features in Web Plus
Web Plus is a highly secure application that can be used to transmit confidential patient data between reporting locations and a central registry safely over the Internet. Security is achieved by a combination of software features and network infrastructure. Security Features of the Web Plus ApplicationForm-based authentication. Web Plus requires each user to enter his or her user ID and password to access the system. Multifactor authentication can be implemented optionally by requiring users to enter a personal identification number and/or by answering challenge questions in addition to providing their user IDs and passwords. Passwords. Web Plus provides several options to configure password attributes. These options can be set by the central registry administrator (see Role-Based Access below). Configurable attributes include—
Personal identification number (PIN). The PIN feature is an additional, optional security feature that accommodates the requirement of two-factor user authentication. When enabled on the systems preference page, the central registry administrator generates a unique random Web Plus PIN Matrix for every user. To login, in addition to their User ID and password, the user must then enter a four-digit PIN based on coordinates from their Web Plus PIN Matrix. Note: PIN Matrix coordinates are provided upon login, and the hosting agency must mail the matrices to users. Challenge questions. The Challenge Question feature is also optional. When enabled on the systems preference page, the central registry administrator enters a series of questions each user must answer when the feature is initially enabled, and answer again upon login to validate the user's identity. The number of challenge questions to answer for initial setup and login is configurable. Role-based access. Web Plus grants users different levels of access depending on their role. Seven roles are defined in Web Plus—
Other Web Plus security features include—
Security Features of the Network InfrastructureSecurity on the client computer. Anti-virus and anti-spyware software should be installed on the client computer, and these programs should be updated regularly. Secure communication channel. Web Plus relies on a Secure Socket Layer (SSL) channel between the Web server and the client browser to protect the data exchanged over the Internet. This secure communication channel is not part of Web Plus, but is required for Web Plus to send data securely. More InformationFor more technical information about data security in Web Plus, read Maximizing Data Security in Web Plus or download Web Plus Security Features and Recommendations (PDF-234KB). Information about data security is also available.
Page last reviewed: March 5, 2009
Page last updated: March 5, 2009 Content source: Division of Cancer Prevention and Control, National Center for Chronic Disease Prevention and Health Promotion |
|
|
|
|
||||||||||||
|