e) change passwords at regular intervals or based on the number of accesses (passwords for privileged accounts should be changed more frequently than normal passwords), and avoid re-using or cycling old passwords; f) change temporary passwords at the first log-on; g) not include passwords in any automated log-on process, e.g. stored in a macro or function key; h) not share individual user passwords; i) not use the same password for business and non-business purposes. All users should be made aware of the security requirements and procedures for protecting unattended equipment, as well as their responsibilities for implementing such protection. Users should be advised to: a) terminate active sessions when finished, unless they can be secured by an appropriate locking mechanism, e.g. a password protected screen saver; b) log-off mainframe computers, servers, and office PCs when the session is finished (i.e. not just switch off the PC screen or terminal); c) secure PCs or terminals from unauthorized use by a key lock or an equivalent control, e.g. password access, when not in use. (NL ISO/IEC, 2010) 4.2. Password Selection Passwords can be effective if selected intelligently and managed properly. A password policy can be part of the organization’s written policy that dictates the requirements for passwords. Many systems also include technical password policies that enforce the password restriction requirements. Password policies can, for example, ensure that users change their passwords regularly (e.g. a maximum age setting might specify that users must change their password every 45 days). The following list includes some other password policy settings: Password length: The length is the number of characters in the password. End user passwords should be at least eight characters long, and many organizations require privileged account passwords to be at least 15 characters long. This specifically overcomes a weakness in how passwords are stored in some Windows systems. Password complexity: The complexity of a password refers to how many character types it includes. An eight-character password using uppercase characters, lowercase characters, symbols, and numbers is much stronger than an eight-character password using only numbers. Password history: Many users get into the habit of switching between two passwords. A password history remembers a certain number of previous passwords (perhaps six) and prevents users from reusing a password in the history. This is often combined with a Lebanese National Security Policy Guidelines v1.7 Page 21 |

Select target paragraph3