Odoo Security Management

Job ID: 39392230

Budget: $10 – $30 USD

I need someone to help manage and explain various aspects of the Odoo system.

Key areas of assistance needed:
Requirement or Security Measure for Odoo Deployment:

The application (main and backup servers) must be hosted in Morocco or within the European Union, in compliance with the GDPR.

A managed services or maintenance contract must be established, clearly detailing the responsibilities of the service provider and interactions with the hosting provider.

Use fictitious (non-production) data during development.

The platform must be accessible only through authorized ports (e.g., HTTPS/443, SSH/22).

The platform must be protected by a firewall and a Web Application Firewall (WAF).

The hosting provider must ensure regular security updates for the platform.

The hosting provider must notify the client in case of any data breach.

The hosting provider must clearly explain its backup policy.

Access to all environments must be encrypted using a trusted SSL certificate.

All operator and user access must be linked to individual (nominative) accounts.

The administrator account must never be used for business/functional tasks.

User sessions must expire after a period of inactivity.

On first login, the user must be forced to change the password set by the administrator.

If the password is reset by the administrator, the user must be forced to change it on next login.

The system must lock the account after 5 failed login attempts.

Users must be able to change their password at any time.

The system must enforce password changes after a configurable duration.

Passwords must not contain the full or partial username.

Passwords must have a minimum length of 10 characters.

Passwords must include at least three of the following categories:

Uppercase English letters (A–Z)

Lowercase English letters (a–z)

Digits (0–9)

Special characters (e.g., !, $, #, %)

Integrate a CAPTCHA that must be validated before submitting any form.

Schedule a workshop with the client to define which input field validations should be implemented.

Uploaded files must only be of types: PDF, JPEG, or PNG.

Files must be encrypted within the platform and only visible to authenticated users.

Sensitive data stored in the database (e.g., revenue figures, passwords, etc.) must be encrypted.

The developer must define how the encryption key is managed and protected.

Only authorized internal users (staff members) can download files for archiving.

External validators can only view documents on the platform.

After the registration process is validated, external validators can only access the validation history.

Log all successful/failed login attempts (including date, time, username, source IP, and reason for failure).

Log all successful/failed sensitive actions (e.g., transaction approvals).

Ideal skills and experience:
knowledge of Odoo


Your expertise will help ensure a secure and well-managed Odoo environment. Please provide detailed bids with relevant experience.
Related categories: Python Odoo