minimum password age setting, preventing users from changing a password repeatedly
until they can set the password back to the original one. Minimum password age is
often set to one day.
However, even with strong software-enforced password restrictions, it remains possible to
create passwords that may be easily guessed or cracked. Users don’t always understand the
need for strong passwords, or even how to create them. An organization’s security policy will
usually stress the need for strong passwords and define the contents of a strong password. If
end users create their own passwords, suggestions like the following can help them create
strong ones:
Do not use any part of your name, logon name, email address, employee number,
Social Security number, phone number, extension, or other identifying name or
code;
Do not use dictionary words (including words in foreign dictionaries), slang, or
industry acronyms;
Do use nonstandard capitalization and spelling;
Do switch letters and replace letters with numbers.
In some environments, initial passwords for user accounts are generated automatically. Often
the generated password is a form of a composition password, which is constructed from two or
more unrelated words joined together with a number or symbol in between. Composition
passwords are easy for computers to generate, but they should not be used for extended
periods of time because they are vulnerable to password-guessing attacks. If the algorithm for
computer-generated passwords is discovered, all passwords created by t he system are in
jeopardy of being compromised. (Stewart et al., 2004)
4.3. Password Phrases
A password mechanism that is more effective than a basic password is a passphrase. A
passphrase is a string of characters similar to a password but it has unique meaning to the user.
Passphrases are often basic sentences modified to simplify memorization. Here’s an example: “I
passed the security exam” can be converted to the following passphrase:
“IP@$$edTheSecurityEx@m.” Using a passphrase has several benefits. It is difficult to crack a
passphrase using a brute-force tool, and it encourages the use of a lengthy string with
numerous characters, but it is still easy to remember. (Stewart et al., 2004)
4.4. Clear Desk and Clear Screen Policy
A clear desk policy for papers and removable storage media and a clear screen policy for
information processing facilities should be adopted.
The clear desk and clear screen policy should take into account the information classifications,
legal and contractual requirements, and the corresponding risks and cultural aspects of the
organization.
Lebanese National Security Policy Guidelines v1.7
Page
22 |