Security Settings
Security Settings
Section titled “Security Settings”NEURO provides comprehensive security controls to protect your organization’s data and ensure compliance with security requirements.
Authentication Security
Section titled “Authentication Security”Password Policy
Section titled “Password Policy”Configure password requirements:
| Setting | Options |
|---|---|
| Minimum length | 8-32 characters |
| Require uppercase | Yes/No |
| Require lowercase | Yes/No |
| Require numbers | Yes/No |
| Require special chars | Yes/No |
| Password history | Prevent last N passwords |
| Maximum age | Days before expiration |
Configuring Password Policy
Section titled “Configuring Password Policy”- Go to Settings → Security
- Navigate to Password Policy
- Set requirements
- Save changes
New passwords must meet policy immediately.
Two-Factor Authentication (MFA)
Section titled “Two-Factor Authentication (MFA)”Enabling MFA
Section titled “Enabling MFA”MFA can be:
- Optional (user choice)
- Required for all users
- Required for admins only
MFA Methods
Section titled “MFA Methods”| Method | Security | Convenience |
|---|---|---|
| Authenticator App | High | Medium |
| Hardware Key | Highest | Lower |
Enforcing MFA
Section titled “Enforcing MFA”- Go to Security → MFA Settings
- Select enforcement level
- Set grace period for setup
- Save
Users without MFA have grace period to configure.
Session Management
Section titled “Session Management”Session Timeout
Section titled “Session Timeout”Configure auto-logout:
- Timeout period: 30 min - 24 hours
- Activity-based: Reset on activity
- Absolute: Fixed session length
Concurrent Sessions
Section titled “Concurrent Sessions”Control multiple logins:
- Allow unlimited
- Limit to N sessions
- Single session only
Session Termination
Section titled “Session Termination”Admins can:
- View active sessions per user
- Terminate specific sessions
- Force logout all users
Access Control
Section titled “Access Control”IP Allowlisting
Section titled “IP Allowlisting”Restrict access by IP address:
- Go to Security → IP Allowlist
- Enable IP allowlisting
- Add allowed IP ranges:
192.168.1.0/2410.0.0.0/8203.0.113.50
- Test with current IP
- Enable enforcement
Geographic Restrictions
Section titled “Geographic Restrictions”Block access from specific regions:
- Select blocked countries
- Or allow specific countries only
API Security
Section titled “API Security”Secure API access:
- Token expiration settings
- IP restrictions for API
- Rate limiting configuration
Data Protection
Section titled “Data Protection”Encryption
Section titled “Encryption”NEURO encrypts data:
| Data Type | Encryption |
|---|---|
| Data at rest | AES-256 |
| Data in transit | TLS 1.3 |
| Backups | AES-256 |
| File uploads | AES-256 |
Data Classification
Section titled “Data Classification”Mark data sensitivity:
- Public
- Internal
- Confidential
- Restricted
Export Controls
Section titled “Export Controls”Control data exports:
- Enable/disable bulk export
- Require admin approval
- Audit all exports
Audit & Compliance
Section titled “Audit & Compliance”Audit Logging
Section titled “Audit Logging”All security events are logged:
| Event Category | Examples |
|---|---|
| Authentication | Login, logout, MFA |
| Authorization | Permission changes |
| Data Access | Views, exports |
| Configuration | Settings changes |
Viewing Audit Logs
Section titled “Viewing Audit Logs”- Go to Security → Audit Logs
- Filter by:
- Date range
- User
- Event type
- Resource
- Export for compliance
Log Retention
Section titled “Log Retention”Configure retention:
- Minimum: 90 days
- Recommended: 1 year
- Maximum: 7 years
Security Monitoring
Section titled “Security Monitoring”Security Dashboard
Section titled “Security Dashboard”View security metrics:
- Failed login attempts
- MFA adoption rate
- Session statistics
- Suspicious activity
Alerts
Section titled “Alerts”Configure security alerts:
- Multiple failed logins
- Login from new location
- Admin action performed
- Export initiated
Incident Response
Section titled “Incident Response”When suspicious activity detected:
- Alert sent to admins
- Option to lock account
- Force password reset
- Session termination
Compliance Features
Section titled “Compliance Features”Compliance Frameworks
Section titled “Compliance Frameworks”NEURO supports compliance with:
- SOC 2 Type II
- GDPR
- HIPAA (with BAA)
- ISO 27001
Evidence Collection
Section titled “Evidence Collection”Export compliance evidence:
- User access reports
- Authentication logs
- Configuration snapshots
- Data handling records
Security Best Practices
Section titled “Security Best Practices”Recommended Settings
Section titled “Recommended Settings”| Setting | Recommendation |
|---|---|
| MFA | Required for all |
| Session timeout | 2 hours |
| Password length | 12+ characters |
| Password expiry | 90 days |
| Failed login lockout | 5 attempts |
Regular Reviews
Section titled “Regular Reviews”Perform periodically:
- User access review (quarterly)
- Admin account audit (monthly)
- Security settings review (quarterly)
- Audit log review (weekly)
Security Checklist
Section titled “Security Checklist”Initial setup:
- Enable MFA requirement
- Configure password policy
- Set session timeouts
- Enable audit logging
- Configure alerts
- Review IP restrictions
Next: Learn about Report Templates