ITS|Loyola University Chicago

ITS

searchform
This siteLUC.edu

Password Standards

EXCEPTIONS

SCOPE

These standards cover the minimum password requirements for all electronic devices owned or leased by Loyola that can be protected by a password.


PURPOSE

To ensure that all electronic devices are secured by a password of a certain complexity. And to ensure that more sensitive devices have more complicated passwords.


STANDARDS

Network passwords - All network passwords will be at least 8 characters long. All network passwords are required to contain at least 2 characters and at least 2 numbers. All network passwords are required to be changed every 180 days. When a network password is changed, it cannot be set to any of its previous 10 values.

Privileged passwords - All passwords for accounts which have additional privileges beyond a normal user must be at least 8 characters long and contain at least 3 character classes (definition in appendix). All privileged passwords are required to be changed every 180 days. All privileged passwords cannot be based on a word that is found in a dictionary. When a privileged password is changed, it cannot be set to its previous value. Privileged passwords cannot be provided to student workers.

Examples of privileged passwords include root, superuser, and administrator passwords for servers, databases, infrastructure devices and other systems. This also includes application accounts that provide rights beyond those of a typical user. If a user is unsure if a given account is privileged, they must assume that it is.

Non network passwords - All devices which do not use the network to authenticate users must follow the same password standards as listed under network passwords. Operating systems which store password history must store the previous 10 passwords. Operating systems which do not store password history must ensure that the new password is different than the previous password.

Mobile device passwords - All mobile devices used to access Loyola email or other Loyola resources must follow the same password standards as listed under network passwords. If the mobile device cannot be configured to confirm that the password meets those standards, then the user of the mobile device is responsible for choosing an appropriate password. Mobile devices must be configured to automatically erase themselves if an incorrect password is entered 10 times in a row.

Mobile devices that cannot be configured with a password and cannot be configured to automatically erase themselves after a certain number of failed password attempts cannot be used to access Loyola email or Loyola resources.

Service passwords -  All passwords used to allow servers to communicate with one another in an automated fashion require stronger passwords as they are infrequently changed. They must be at least 20 characters long, and contain at least 2 characters from each of the 4 character classes. Service passwords cannot be provided to student workers.

High Security Accounts - All passwords used on systems that store, transmit or process Loyola Protected, per the Data Classification Policy, data will conform to the following extra password requirements:

  • The password will be changed every 90 days.
  • New passwords may not be the same as the last four passwords.
  • Accounts will be locked out for thirty minutes after six failed login attempts.
  • First time passwords will be set to a unique value for each user. Passwords will be set to change immediately after first use.

Noncompliance - If a mobile device that does not meet these standards is connected to Loyola email or other Loyola resources, the end user must consult with the Information Security team at DataSecurity@luc.edu to discuss the situation. The Information Security team will advise the end user on the type of password that should be used.


EXCEPTIONS

Exceptions to this policy will be handled in accordance with the ITS Security Policy.

REVIEW

This policy will be maintained in accordance with the ITS Security Policy.

APPENDIX

Documents Referenced

Data Classification Policy

ITS Security Policy

Definitions Character classes There are four character classes available. The four classes are numbers, lowercase letters, uppercase letters, and special characters. Special characters are those characters that can be typed on a computer that do not fall into one of the other three classes.

Student worker A student worker is an individual who is enrolled in at least one class at Loyola, is hired in a position that is not eligible for benefits, and works in a temporary capacity. This includes hourly employees and temporary part time (TPT) workers. This does not include permanent part time (PPT) workers or full time employees (FTE).

Exception example -  If a system treats uppercase and lowercase characters as the same, and does not accept special characters, it is impossible to create a privileged password using our standards. In this case, the password would have a length of 8 characters (matching the standard) and would contain both characters and numbers (2 classes being as close to the standard of 3 as possible).

Known systems that require exceptions Blackberry mobile devices Minimum length can be checked, password complexity cannot. Password requirements will be communicated to the end user.

HISTORY

 April 20, 2007: Initial Policy

September 30, 2008: Added "High Security Accounts" standard

October 29, 2012: Annual Review for PCI Compliance

 Author: UISO

Version: 1.1