3.2 Use SECURE Setting For Cookies3.5 Limit Use of UUID3.7 Institute Local Session Timeout3.10 Hide Account Numbers and Use Tokens3.13 Avoid Storing App Data in Backups