Anda di halaman 1dari 2

Information Security Standards

Title Secure Password Standards Reference No 02.03.01


Version No 2.0 Status Final
Creation Date November 20, 2007 Revision Date 01/15/2013
Approval Date February 22, 2013 Approved by Policy Approval
Committee
Applicability Confidential and protected

Statement of Policy

Washington University School of Medicine (WUSM) is committed to conducting business in compliance


with all applicable laws, regulations and WU policies. WUSM has adopted this policy to outline the
security measures required to protect electronic information systems and related equipment from
unauthorized use.

Objective

This standard covers the unique user identification and passwords that will apply to electronic information
systems that maintain protected information.

Standards

In order to connect to WUSM confidential or protected information workforce members must comply with the
following password standards.
Passwords must be random and required to change on the first login.
A default password will not be given to all workforce members.
WUSM IT Support groups will only reset password when the workforce members identity has been
verified.
WUSM IT Support groups will not ask for workforce members passwords via email.
Passwords are not to be shared.
Refrain from writing passwords down. Use encrypted password vaults to store passwords if
necessary.
Passwords should not be easily guessed (i.e. children or pets name, favorite teams, or information
easily obtained about you online).
Passwords should not be stored or remembered by applications, especially when not using your
normal workstation (i.e. kiosks, common workstations, friends or families computers)
Contact the WUSM IT Support group to reset your passwords if you suspect it has been
compromised.
WUSM workforce members must not circumvent password entry with auto logon, application
remembering, embedded scripts or had coded passwords in client software except where approved
by the Information Security Office.
Password protected screen savers or logging off the device is required when systems are unattended.
Information Security Standards

WUSM passwords / passphrases are required to meet one of the following criteria:

Eight Character Fifteen Character


Incorporate 3 of the following characteristics: A passphrase containing at least 15 characters
Any lower case letters (a-z)
Any upper case letters (A-Z)
Any numbers (0-9)
Any punctuation or non-alphanumeric
characters found on a standard ASCII
keyboard (!@#$%^&*()_+=={}[]:;|\/?<>,.~`)
Passwords must not include easily guessed information Consist of 3 or more unique words
(personal information, names, pets, birth dates, etc.) or
words found in a Dictionary
Individual user passwords must be changed (i.e. expire) Annual expiration
at least every 120 days for WUSM accounts

If a system does not support the minimum structure and complexity as listed above, an exception form must be
completed and a risk assessment will be performed by the Information Security Office. 01.01.01.04 Policy Exception
Request Form

Anda mungkin juga menyukai