minimum password age setting, preventing users from changing a password repeatedly until they can set the password back to the original one. Minimum password age is often set to one day. However, even with strong software-enforced password restrictions, it remains possible to create passwords that may be easily guessed or cracked. Users don’t always understand the need for strong passwords, or even how to create them. An organization’s security policy will usually stress the need for strong passwords and define the contents of a strong password. If end users create their own passwords, suggestions like the following can help them create strong ones:  Do not use any part of your name, logon name, email address, employee number, Social Security number, phone number, extension, or other identifying name or code;  Do not use dictionary words (including words in foreign dictionaries), slang, or industry acronyms;  Do use nonstandard capitalization and spelling;  Do switch letters and replace letters with numbers. In some environments, initial passwords for user accounts are generated automatically. Often the generated password is a form of a composition password, which is constructed from two or more unrelated words joined together with a number or symbol in between. Composition passwords are easy for computers to generate, but they should not be used for extended periods of time because they are vulnerable to password-guessing attacks. If the algorithm for computer-generated passwords is discovered, all passwords created by t he system are in jeopardy of being compromised. (Stewart et al., 2004) 4.3. Password Phrases A password mechanism that is more effective than a basic password is a passphrase. A passphrase is a string of characters similar to a password but it has unique meaning to the user. Passphrases are often basic sentences modified to simplify memorization. Here’s an example: “I passed the security exam” can be converted to the following passphrase: “IP@$$edTheSecurityEx@m.” Using a passphrase has several benefits. It is difficult to crack a passphrase using a brute-force tool, and it encourages the use of a lengthy string with numerous characters, but it is still easy to remember. (Stewart et al., 2004) 4.4. Clear Desk and Clear Screen Policy A clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities should be adopted. The clear desk and clear screen policy should take into account the information classifications, legal and contractual requirements, and the corresponding risks and cultural aspects of the organization. Lebanese National Security Policy Guidelines v1.7 Page 22 |

Select target paragraph3