SRS-087 Use hashed and salted passwords
Identifier​
SRS-087
Software System​
- Authentication Service
Category​
- Security
Description​
Because the software must authenticate users and securely manage their credentials (both at rest and in transit), it falls squarely under the need to protect and periodically refresh authenticators. Specifically, the REST API uses username and password credentials to generate tokens that must remain confidential, be changeable from default values, and be securely stored.
Derived from PRS​
PRS-9F2
: Cybersecurity & continuous threat detection