|
New Hanover County Information Technology Department |
Issued: 11/01/01 |
|
|
Policy Number: 5-01 |
||
|
Subject: Password Policy |
||
The purpose of this policy is to protect County
data and assets by establishing a standard for creation of strong passwords, the
protection of those passwords, and the frequency of change.
Passwords are an important aspect of computer security. They are the
front line of protection for user accounts.
A poorly chosen password may result in the compromise of
The scope of this policy includes all personnel who
have or are responsible for an account (or any form of access that supports or
requires a password) on any system that resides at any New Hanover County
facility, has access to the New Hanover County network, or stores any non-public
New Hanover County information.
None.
This is the Original Document
1)
General:
·
All
·
NHC uses Microsoft’s “Active
Directory” network directory product to control many aspects of a password
policy such as minimum length, complexity, age, etc. and is the baseline for
password management for the County.
·
The New
Hanover County IT Department will insure that Active Directory is configured to
meet the password requirements in this document.
Any Information System that is not running a Microsoft Windows operating
system or is not controlled by Active Directory, such as AS400’s, Linux
Operating Systems, and systems that are not members of the County network, must
be identified by the owner of the system to New Hanover County IT Department.
These systems will be configured to meet as many of the requirements of
this policy as possible and a decision will be made if the security of these
systems is satisfactory.
·
The Human Resources Department will make
all employees aware of this policy.
·
All
contractors and vendors that are given access to New Hanover County non-public
information or are given access to New Hanover County Information Systems, must
have read and understand this policy.
2)
Minimum
Password Requirements:
·
Password
History:
A user cannot submit a new password that is the same as any of the last four
passwords used.
·
Maximum
Password Age:
Passwords will be changed at least every 90 days.
·
Minimum
Password Age:
2 days.
·
Minimum
Password Length:
7 characters
·
Minimum
Password Complexity:
The password
contains characters from at least three of the following four categories:
o
English
uppercase characters (A - Z)
o
English
lowercase characters (a - z)
o
Digits (0 -
9)
o
Non-alphanumeric (for example: !, $, #, or %)
·
Password
Uniqueness:
The password
does not contain three or more characters from the user's account name.
3)
Password Protection Standards
Here is a list of "Dont's:":
o
Don't reveal
a password over the phone to ANYONE
o
Don't reveal
a password in an email message
o
Don't reveal
a password to the boss
o
Don't
talk about a password in front of others
o
Don't hint at
the format of a password (e.g., "my family name")
o
Don't reveal
a password on questionnaires or security forms
o
Don't share a
password with family members
o
Don't reveal
a password to co-workers
while on vacation
4)
Enforcement:
a)
Any employee found to have
willfully violated this policy may be subject to disciplinary action, up to and
including termination of employment.
General Password Construction
Guidelines
Passwords are used for various
purposes at
·
Strong passwords have the
following characteristics:
o
Contain both
upper and lower case characters (e.g., a-z, A-Z)
o
Have digits
and punctuation characters as well as letters
e.g., 0-9,!@#$%^&*()_+|~-=\`{}[]:";'<>?,./
o
Are not words
in any language, slang, dialect, jargon, etc.
o
Are not based
on personal information, names of
family, etc.
o
Passwords
should never be written down or stored on-line.
o
Try to create
passwords that can be
easily remembered.
·
Passphrases
are often used as passwords.
o
Passphrases
are
generally longer than passwords, for example “Ohmy1stubbedmyt0e”.
o
One way to create a passphrase
is to base it on a song title, affirmation, or other phrase. For example, the
phrase might be: "This May Be One Way To Remember" and the password could be:
"TmB1w2R!" or "Tmb1W>r~" or some other variation.
Change History:
|
Version |
Date |
Author |
Comments |
|
A |
09/11/07 |
LSC |
Original Document |
|
|
09/21/07 |
LSC |
Incorporated Mgmt Team Changes for approved policy |
|
|
|
|
|
|
|
|
|
|