e) change passwords at regular intervals or based on the number of accesses
(passwords for privileged accounts should be changed more frequently than normal
passwords), and avoid re-using or cycling old passwords;
f) change temporary passwords at the first log-on;
g) not include passwords in any automated log-on process, e.g. stored in a macro or
function key;
h) not share individual user passwords;
i) not use the same password for business and non-business purposes.
All users should be made aware of the security requirements and procedures for protecting
unattended equipment, as well as their responsibilities for implementing such protection.
Users should be advised to:
a) terminate active sessions when finished, unless they can be secured by an
appropriate locking mechanism, e.g. a password protected screen saver;
b) log-off mainframe computers, servers, and office PCs when the session is finished
(i.e. not just switch off the PC screen or terminal);
c) secure PCs or terminals from unauthorized use by a key lock or an equivalent
control, e.g. password access, when not in use.
(NL ISO/IEC, 2010)
4.2. Password Selection
Passwords can be effective if selected intelligently and managed properly. A password policy
can be part of the organization’s written policy that dictates the requirements for passwords.
Many systems also include technical password policies that enforce the password restriction
requirements. Password policies can, for example, ensure that users change their passwords
regularly (e.g. a maximum age setting might specify that users must change their password
every 45 days). The following list includes some other password policy settings:
Password length: The length is the number of characters in the password. End user
passwords should be at least eight characters long, and many organizations require
privileged account passwords to be at least 15 characters long. This specifically
overcomes a weakness in how passwords are stored in some Windows systems.
Password complexity: The complexity of a password refers to how many character
types it includes. An eight-character password using uppercase characters, lowercase
characters, symbols, and numbers is much stronger than an eight-character password
using only numbers.
Password history: Many users get into the habit of switching between two passwords. A
password history remembers a certain number of previous passwords (perhaps six) and
prevents users from reusing a password in the history. This is often combined with a
Lebanese National Security Policy Guidelines v1.7
Page
21 |