Security Settings

You can configure global security settings for ASM Core, including password settings and integration.

Enabling Integrated Security

Integrated Security allows Analysts to use their workstation login ID and password to access ASM Core. This means that when they launch ASM Core, they do not need to enter a username and password, which makes logging in quicker. However, it also means that only the Analyst logged in to a particular workstation can access ASM Core from that workstation. You will still need to select the system you want to work with if there is more than one (such as Dev, Test, etc).

If you want to log in using the default Admin account and use integrated security, append noauth=true to the system URL to bring up the login window (e.g.: .../core.aspx?noauth=true). However, most administration functions can be performed by any Analyst as long as they have the permissions through their General Access security role.

Using Integrated Security and Directory Integration

If your system is configured for Active Directory integration through the Integration Platform Settings, Alemba recommends that you enable Integrated Security. If it is enabled for another type of directory server integration and Authenticate Imported People against Source is selected in the Integration Source Details for this directory server, this setting is ignored.

If you enable integrated security and select Authenticate Imported People against Source in the Integration Source Details for the directory server, a person record imported through a directory server integration scan will be authenticated using the details stored in the ASM database or the directory server. If you do not enable integrated security, people logging in will be authenticated using the details stored in the ASM database.

Before you start

Enable Windows Authentication and disable Anonymous Authentication for the related virtual directory in IIS on the web server where ASM Core is installed.

Select Default Self Service Portal for the system in the ASM Core Server Console as explained in the Server Console Guide.

Ensure that you have Security Setup selected in the Admin tab of your General Access security role to access the Security options within the System window.

  1. Select the Menu button , then Admin, and then select System Administration.

    The System Administration window is displayed, with a menu of options available. In the Explorer pane, expand Security.

  2. Select the Security Settings option. The Security Settings window appears. Select the appropriate settings for your system:

Full Application and HTML Only

Enables ASM Core to automatically take the login details (username and password) from the workstation log in for the main application and the HTML Only interface.

This means that the ASM Core login for an Analyst must match their workstation login.

Self Service Portal

Enables integrated security on the Self Service Portal. If this option is cleared, Users must log into the Self Service Portal manually with their ASM Core username and password.

Passwords Required for Authorization/Approval

Select this to force Analysts to enter a password when authorizing requests and completing approvals.

This option only becomes enabled if one of the previous options is selected.

This setting is ignored when attempting to be used in combination with SSO, which is configured in the Integration settings.

Configuring Security Settings for Passwords

You can configure the security settings for Passwords that are used to log into ASM Core.

  1. Select the Menu button , then Admin, and then select System Administration.

    The System Administration window is displayed, with a menu of options available. In the Explorer pane, expand Security.

  2. Select the Security Settings option from the Explorer pane to display the Security Settings window. The Password Configuration options are in the second section of the window.

Password Policy

The password Policy allows you to control local ASM password policies in ASM. When security is integrated, external password policies will inform the users password.

The following Attributes are available to control password complexity and other parameters:

  • Upper Case

  • Lower Case

  • Number

  • Special Characters

  • Does not contain part of Name, Login ID, or email

  • Minimum Length (6 by default, you can alter this figure)

  • Password History (prevents reusing the same password and allows you to specify how many passwords are remembered.)

  • Minimum period between changes (you can set a figure in hours)

  • Password Expiry (When checked, passwords will expire at the given interval you enter)

  • Encrypt Password (This encrypts the password in the database)

  • Disable access on login failure (you will then specify how many failed attempts it takes to disable access and whether or not you want a call loggged automatically. See Security Settings/Partitioned)

  • Reset Password when forgotten automation

  • reCaptcha

Common Password Blacklist

ASM contains a common password blacklist that when enabled, you may update as required.