The following points were asked by HDFC Team for Inbound IVR Audit Points as Evidence.
1.Dormancy parameters configuration for New and Existing Users. (Provide screenshot of Admin console else backend coding screenshot)
Provide screenshot for Application password policy
Password expiry: Not Set
Password history: 05 - Not Ok
Failed login attempts: Not Set
Passwords should be changed at first logon - Not set
Presence of two factor authentication for internet facing applications. - Not set
3.Evidence for interfacing applications.(Provide screenshot of backend where the APIs are present)
Token Generation and Get Data API
Salesforce
iSAC
Patch management details for the application (Kamalio).
Phonon Replies:
Dormancy parameters configuration for New and Existing Users. (Provide screenshot of Admin console else backend coding screenshot)
Active Agents:
b. Pending Agents
Provide screenshot for Application password policy
Password expiry: Set.
Password history: 05, Cannot use last 5 passwords
Failed login attempts: Not Set (Video link has been shared)
Passwords should be changed at first logon - Not set (As passwords are set up by agents while signing up their phonon account)
Presence of two factor authentication for internet facing applications. - Presence of two factor authentication for internet facing applications. - Not set - Already in process and also discussed with Neeraj Sir and Keyur Vasani.
.Evidence for interfacing applications.(Provide screenshot of backend where the APIs are present)
Token Generation: https://capi.hdfc.com/Mowbly_api_live_dmz/api/Mowbly/GetData
Get Data API : https://capi.hdfc.com/Mowbly_api_live_dmz/api/Mowbly/GetData
Salesforce
SF-GetAccountIDByFileNo : https://hdfclimited.my.salesforce.com/services/data/v57.0/query/?q=select id from opportunity where HDFC_DASH_File_Number__c='$flow.key.i_filenumber'
Open Page: https://central.phonon.io/socket/api/publish
Query_SF Push : https://hdfclimited.my.salesforce.com/services/data/v57.0/sobjects/Case
Request_SF Push : https://hdfclimited.my.salesforce.com/services/data/v57.0/sobjects/Case
Loan_Complain_SF_Push : https://hdfclimited.my.salesforce.com/services/data/v57.0/sobjects/Case
Deposit_Complian_SF Push: https://hdfclimited.my.salesforce.com/services/data/v57.0/sobjects/Case
iSAC ( Not having access to this)
Patch management details for the application (Kamalio):- Already discussed with Sachin Srivastav.