a) Users should be required to sign a statement to keep personal passwords ;
b) confidential and to keep group passwords solely within the members of the group;
c) When users are required to maintain their own passwords they should be provided
initially with a secure temporary password, which they are forced to change
immediately;
d) Temporary passwords should be given to users in a secure manner;
e) temporary passwords should be unique to an individual and should not be
guessable;
f) passwords should never be stored on computer systems in an unprotected form;
Passwords are a common means of verifying a user’s identity before access is given to an
information system or service according to the us er’s authorization. Other technologies for user
identification and authentication, such as biometrics, e.g. finger-print verification, signature
verification, and use of hardware tokens, e.g. smart cards, are available, and should be
considered if appropriate. (NL ISO/IEC, 2010)
4. User Responsibilities
To prevent unauthorized user access, and compromise or theft of information and information
processing facilities.
The co-operation of authorized users is essential for effective security. (NL ISO/IEC, 2010)
4.1. Password Use
Users should be required to follow good security practices in the selection and use of
passwords.
All users should be advised to:
“Treat your password like your
a) keep passwords confidential;
toothbrush. Don’t let anybody else
b) avoid keeping a record (e.g. paper,
use it, and get a new one every six
software file or hand-held device) of
months.”
passwords, unless this can be stored
securely and the method of storing has
– Clifford Stoll – American
astronomer,
author and teacher
been approved;
c) change passwords whenever there is any
indication of possible system or password compromise;
d) select quality passwords with sufficient minimum length which are:
1) easy to remember;
2) not based on anything somebody else could easily guess or obtain using
person related information, e.g. names, telephone numbers, and dates of
birth etc.;
3) not vulnerable to dictionary attacks (i.e. do not consist of words included in
dictionaries);
4) free of consecutive identical, all-numeric or all-alphabetic characters.
Lebanese National Security Policy Guidelines v1.7
Page
20 |