Increased Security In Vestigo (2022)
Increased Security
The McCreadie Group regularly updates Vestigo to keep your data secure. With the 5.3.4 Vestigo Point Release scheduled for late April, we will be adding an extra layer of security to several Vestigo processes.
When will these Changes Occur?
The 5.3.4 release is scheduled for late April or early May; however, you will work with the Vestigo team to implement the changes in a time frame that works best for your site.
What will be Changing?
Users will log in to Vestigo using their email address instead of their username. Usernames will still be used in Vestigo for all transactions.
Users will receive an account activation link in their email to set their password rather than an email with their credentials.
Sites will be able to utilize functionality that requires users to re-authenticate their credentials with a PIN when verifying dispenses (e-signature to support 21 CFR Part 11 compliance). There will be other options available, so please speak with your account manager if your site prefers a different method of validation. The Vestigo team will work with each site to implement this functionality.
Why are these Changes Necessary?
Vestigo will begin utilizing Okta, an identity management solution, to strengthen authentication. Granting roles (authorization) will continue in Vestigo. This integration will increase security to better align with your policies and help ensure that your account and Vestigo data stays secure. For example, Okta will support several Multi-Factor Authentication (MFA) options that can serve as an e-signature to validate dispenses. And as remote, or partially remote, monitoring visits continue to be the norm, Okta will add an additional layer of security to protect access to your data.
What can I do to Prepare?
Prior to your site’s implementation, communicate the changes to your team and encourage all users to log in. This will help the software to transition quickly with up-to-date passwords. As the time grows closer, you will be provided with resources and instructions during implementation.
Consider enabling SSO SAML authentication for your site to streamline access. SSO SAML allows users to use their network credentials to log in to Vestigo.
Determine which method of validating dispenses will work best for your team: PIN, a notification sent to the user’s phone, or a fingerprint. We will default to requiring a PIN unless you specify a different option.
Please contact support@mccreadiegroup.com with any questions or concerns.