CCASS/3 - Frequently Asked Questions 
11/08/2009 
 

IV

Security Management : Delegated Management System (DMS)

Smartcard and Smartcard Reader
Q19What is the security measure for Participant to log on CCASS/3?
Q20How many smartcards will be issued to each Participant?
Q21Can a Participant use the same smartcard to access different C3T?
Q22Can Participants install the smartcard reader in a slim PC or is the smartcard reader an external device?
Q23Is smartcard reader required for all C3Ts?
Segregation of Duty
Q24Can a Participant assign a single user as a Delegated Administrator (DA) handling both the maker and checker functions?
Q25Can Participants assign operational staff as DA?
Q26Can a Participant assign more than one checker or maker to handle the DA functions?
Q27Will separate set of smartcards be issued to DA maker and checker?
Q28Can a DA checker use relevant maker's smartcard to access CCASS/3 and vice versa?
Q29What is the main difference between the functions of a DA maker & a DA checker?
Q30In what situation should a DA checker use the smartcard to logon CCASS/3?
Q31Is there a transaction limit assigned to each DA?
Authorization Code
Q32If a DA checker wrongly inputs the checker ID three times, will the DA authorization code be revoked?
Q33Are DA checkers required to memorize the authorization code?
Q34How often will the authorization code be changed?
DA’s Operations
Q35Are DAs required to initialize their smartcards?
Q36Can a DA maker's smartcard remain in the smartcard reader while relevant DA checker authorizes a transaction?
Q37If an operation user resigns from the company and his job is taken up by another user, can the DA assign a new user name and user profile to the resigned user's smartcard?
Q38Are Participants required to change the passwords of the smartcards for DA makers and checkers?
Q39If the DA resets the password for a user, is the user concerned required to change the password at the first log-on?
Q40Is there any charge on the DA smartcard?
Q41When a DA set up a user profile, is it compulsory for the DA to input the “enabled date” and “disabled date”?