The Sarbanes-Oxley Act (SOX) was passed in 2002 by the United States government to protect shareholders and the public from accounting errors and fraudulent activities in organizations. SOX compliance requires public firms to identify and protect all financial management resources, including reports, applications, supporting systems, and services, according to the specified standards. Noncompliance can result in fines, imprisonment, or both.
SOX does not mention any specific requirements concerning passwords or identity authentication for financial systems. However, financial organizations aiming to achieve holistic compliance with SOX are encouraged to adopt the following password and authentication best practices.
Passwords longer than 20 characters are difficult to crack. Hackers have to try numerous different combinations and still might not be able to guess the correct password when it is long enough.
Using common words and numbers like password, admin, or 12345 in passwords makes them vulnerable to compromise. Passwords like these can be easily guessed during a potential dictionary attack.
Passphrases, in contrast to passwords, are longer and easier to remember yet harder to crack. It could be something like Purple skies @nd pumpk1n seeds! This meets password complexity requirements and is quite catchy, making it hard to forget.
Reusing old passwords or fragments of them might be convenient for users to remember, but it significantly increases the risk of those passwords being compromised. To improve password security, it is essential to prevent users from reusing old passwords.
Using personal information in passwords, such as usernames and birth dates, makes it easy for attackers to guess and breach them. Users are advised to choose passwords that do not contain any personal information in them.
Having unsafe passwords as the only defense strategy poses a huge risk to underlying resources. To enhance identity security, users should be authenticated with strong MFA methods—such as biometrics, TOTPs, and security keys—alongside passwords.
When password reset requests are sent to a help desk, there might not be an identity verification process to ensure that the request is legitimate. Moreover, when new passwords are given in plaintext over a messaging application, this increases the possibility of password theft. Self-service password management is a more secure, convenient option that overcomes such challenges.
ADSelfService Plus enables your organization to implement password management best practices with ease using the Password Policy Enforcer. Using custom policies that can be applied to chosen users, groups, or OUs in AD, you can enforce specific password and authentication requirements for users with varying access privileges for financial resources.
Prevent users from using common words and repeated patterns in passwords.
Configure the minimum and maximum user password length.
Choose the minimum number of complexity requirements your users' passwords should satisfy according to your organization's security needs.
Prevent users from using common words and repeated patterns in passwords.
Configure the minimum and maximum user password length.
Choose the minimum number of complexity requirements your users' passwords should satisfy according to your organization's security needs.
Secure user access to all enterprise applications and endpoints in your network using MFA.
Choose from 20 different authenticators to verify your users' identities.
Secure user access to all enterprise applications and endpoints in your network using MFA.
Choose from 20 different authenticators to verify your users' identities.
Free Active Directory users from attending lengthy help desk calls by allowing them to self-service their password resets/ account unlock tasks. Hassle-free password change for Active Directory users with ADSelfService Plus ‘Change Password’ console.
Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications with their Active Directory credentials. Thanks to ADSelfService Plus!
Intimate Active Directory users of their impending password/account expiry by mailing them these password/account expiry notifications.
Synchronize Windows Active Directory user password/account changes across multiple systems, automatically, including Office 365, G Suite, IBM iSeries and more.
Ensure strong user passwords that resist various hacking threats with ADSelfService Plus by enforcing Active Directory users to adhere to compliant passwords via displaying password complexity requirements.
Portal that lets Active Directory users update their latest information and a quick search facility to scout for information about peers by using search keys, like contact number, of the personality being searched.