Laserfiche WebLink
Questionnaire Form <br />TD Bank understands the importance of security; therefore, varying degrees of authorization can <br />be established at the user level by the System Administrator, (initiators, approvers, dollar limits, <br />etc.). The City will have the convenience of initiating ACH transactions and wire transfers <br />electronically through TD eTreasury while maintaining appropriate payment initiation controls. <br />User profiles established by your System Administrator govern the level of ACH and wire authority <br />for each user (create, approve, create templates, etc.) and associated dollar limits. <br />As an enhanced security feature, two users are needed to create and approve ACH transactions <br />and wire transfers for dual control purposes. The system allows you to create free form and <br />repetitive templates. Users may also choose to create an alert to notify them when an ACH or <br />wire is pending their approval. <br />A.Does session inactivity cause a sign-off? After how long? <br />Users are timed-out after 30 minutes of inactivity. <br />B.How are form entries protected against common attacks like SQL injection, buffer overflow, Cross-site <br />scripting, etc. <br />UOB has implemented a series of servlet filters that scan for SQL injection and XSS attacks. <br />Dynamic scanning tools are employed to test the effectiveness of these filters. <br />C.What web server software are you using? <br />IBM Web application server (IHS) <br />D.What internet browsers is your software compatible with? Are there any exceptions or limitations? <br />Recommended browsers are Microsoft Internet Explorer 8.0 or above, Firefox 3.6 or above; <br />Safari 5.0 or above; Google Chrome 6.5 or above. <br />E.Describe procedures to test and install manufacturer’s security patches when issued. <br />TD has a monthly patching cycle for OS patches and quarterly patching cycle for database. <br />Application patches are available through vendor software releases. <br />F.Do your web based applications conform to “Open Web Application Security Project” (OWASP) <br />Standards? http://www.owasp.org. <br />Yes UOB confirms to the OWASP standards. <br />Proposed by: TD Bank, N.A.Page 86 <br /> <br />