SRS-087 Use hashed and salted passwords
Identifier
SRS-087
Software System
- Authentication Service
 
Category
- Security
 
Description
Because the software must authenticate users and securely manage their credentials (both at rest and in transit), it falls squarely under the need to protect and periodically refresh authenticators. Specifically, the REST API uses username and password credentials to generate tokens that must remain confidential, be changeable from default values, and be securely stored.
Derived from PRS
PRS-9F2: Cybersecurity & continuous threat detection