a) Users should be required to sign a statement to keep personal passwords ; b) confidential and to keep group passwords solely within the members of the group; c) When users are required to maintain their own passwords they should be provided initially with a secure temporary password, which they are forced to change immediately; d) Temporary passwords should be given to users in a secure manner; e) temporary passwords should be unique to an individual and should not be guessable; f) passwords should never be stored on computer systems in an unprotected form; Passwords are a common means of verifying a user’s identity before access is given to an information system or service according to the us er’s authorization. Other technologies for user identification and authentication, such as biometrics, e.g. finger-print verification, signature verification, and use of hardware tokens, e.g. smart cards, are available, and should be considered if appropriate. (NL ISO/IEC, 2010) 4. User Responsibilities To prevent unauthorized user access, and compromise or theft of information and information processing facilities. The co-operation of authorized users is essential for effective security. (NL ISO/IEC, 2010) 4.1. Password Use Users should be required to follow good security practices in the selection and use of passwords. All users should be advised to: “Treat your password like your a) keep passwords confidential; toothbrush. Don’t let anybody else b) avoid keeping a record (e.g. paper, use it, and get a new one every six software file or hand-held device) of months.” passwords, unless this can be stored securely and the method of storing has – Clifford Stoll – American astronomer, author and teacher been approved; c) change passwords whenever there is any indication of possible system or password compromise; d) select quality passwords with sufficient minimum length which are: 1) easy to remember; 2) not based on anything somebody else could easily guess or obtain using person related information, e.g. names, telephone numbers, and dates of birth etc.; 3) not vulnerable to dictionary attacks (i.e. do not consist of words included in dictionaries); 4) free of consecutive identical, all-numeric or all-alphabetic characters. Lebanese National Security Policy Guidelines v1.7 Page 20 |

Select target paragraph3