New Hanover County

Information Technology Department

Issued:  11/01/01

Policy Number:  5-01

Subject:  Password Policy


PURPOSE AND SCOPE

The purpose of this policy is to protect County data and assets by establishing a standard for creation of strong passwords, the protection of those passwords, and the frequency of change.  Passwords are an important aspect of computer security. They are the front line of protection for user accounts.  A poorly chosen password may result in the compromise of New Hanover County's entire network. A comprehensive and secure password policy is mandated for New Hanover County by a number of different agencies or regulations, such as HIPAA, PCI, FBI, DCI, and others.

The scope of this policy includes all personnel who have or are responsible for an account (or any form of access that supports or requires a password) on any system that resides at any New Hanover County facility, has access to the New Hanover County network, or stores any non-public New Hanover County information.

CHANGE SUMMARY

None.  This is the Original Document

POLICY

1)    General:

·        All New Hanover County employees (including contractors and vendors with access to New Hanover County systems) must comply with this policy.

·        NHC uses Microsoft’s “Active Directory” network directory product to control many aspects of a password policy such as minimum length, complexity, age, etc. and is the baseline for password management for the County.

·        The New Hanover County IT Department will insure that Active Directory is configured to meet the password requirements in this document.  Any Information System that is not running a Microsoft Windows operating system or is not controlled by Active Directory, such as AS400’s, Linux Operating Systems, and systems that are not members of the County network, must be identified by the owner of the system to New Hanover County IT Department.  These systems will be configured to meet as many of the requirements of this policy as possible and a decision will be made if the security of these systems is satisfactory. 

·         The Human Resources Department will make all employees aware of this policy.

·        All contractors and vendors that are given access to New Hanover County non-public information or are given access to New Hanover County Information Systems, must have read and understand this policy.

2)    Minimum Password Requirements:

·        Password History: A user cannot submit a new password that is the same as any of the last four passwords used.

·        Maximum Password Age: Passwords will be changed at least every 90 days.

·        Minimum Password Age: 2 days.

·        Minimum Password Length: 7 characters

·        Minimum Password Complexity: The password contains characters from at least three of the following four categories:

o   English uppercase characters (A - Z)

o   English lowercase characters (a - z)

o   Digits (0 - 9)

o   Non-alphanumeric (for example: !, $, #, or %)

·        Password Uniqueness:  The password does not contain three or more characters from the user's account name.

3)    Password Protection Standards


Here is a list of "Dont's:":

o   Don't reveal a password over the phone to ANYONE

o   Don't reveal a password in an email message

o   Don't reveal a password to the boss

o   Don't talk about a password in front of others

o   Don't hint at the format of a password (e.g., "my family name")

o   Don't reveal a password on questionnaires or security forms

o   Don't share a password with family members

o   Don't reveal a password to co-workers while on vacation

4)    Enforcement:

a)    Any employee found to have willfully violated this policy may be subject to disciplinary action, up to and including termination of employment.

General Password Construction Guidelines

Passwords are used for various purposes at New Hanover County. Some of the more common uses include: user level accounts, web accounts, email accounts, screen saver protection, voicemail password, and local router logins. Everyone should be aware of how to select strong passwords.

·        Strong passwords have the following characteristics:

o   Contain both upper and lower case characters (e.g., a-z, A-Z)

o   Have digits and punctuation characters as well as letters e.g., 0-9,!@#$%^&*()_+|~-=\`{}[]:";'<>?,./

o   Are not words in any language, slang, dialect, jargon, etc.

o   Are not based on personal information, names of family, etc.

o   Passwords should never be written down or stored on-line.

o   Try to create passwords that can be easily remembered.

·        Passphrases are often used as passwords.

o    Passphrases are generally longer than passwords, for example “Ohmy1stubbedmyt0e”.

o   One way to create a passphrase is to base it on a song title, affirmation, or other phrase. For example, the phrase might be: "This May Be One Way To Remember" and the password could be: "TmB1w2R!" or "Tmb1W>r~" or some other variation.

Change History:

Version

Date

Author

Comments

A

09/11/07

LSC

 Original Document

 

09/21/07

  LSC

Incorporated Mgmt Team Changes for approved policy