Policy 7.2 - Password Requirements

Policy 7.2 - Password Requirements

BLACK HILLS STATE UNIVERSITY

Policy and Procedure Manual

SUBJECT: Password Requirements

NUMBER: 7:2

Office/Contact: Network and Computer Services (NCS)

Source: SDBOR Policies 7.1 and 7:4

Purpose

This policy establishes the University’s standard for creating and protecting strong passwords.

Definitions

  1. Compromise - made vulnerable (as to attack or misuse) by unauthorized access, revelation, or exposure.

Policy

  1. Passwords have no expiration date
  2. Passwords must be changed if there is suspicion of compromise or if the password has been compromised.
  3. All passwords must be strong passwords, as defined below.
  4. General Password Construction Standards
    1. Strong passwords contain the following characteristics:
      1. Contain at least three (3) of the four (4) following character classes:
        1. Lowercase characters
        2. Upper case characters
        3. Numbers
        4. Special characters (e.g., $%^&*() _+= etc.)
      2. Passwords must contain fifteen (15) or more alphanumeric characters
    2. Weak passwords contain the following characteristics:
      1. Fewer than fifteen (15) characters
      2. Common usage words such as:
        1. Names of family, pets, friends, co-workers, etc.
        2. Birthdays and other personal information
        3. Letter or number patterns (e.g., qwerty, 12345, etc.)
  5. Password Protection Standards
    1. Passwords shall not be shared with anyone. Sharing or allowing another individual to use an account password violates SDBOR Policy 7.1 (Acceptable Use Policy). All passwords are to be treated as sensitive, confidential information.
      1. Network and Computer Services, as a function of operation, may ask users for their passwords for technical support services. These instances do not violate SDBOR Policy 7:1.
      2. Network and Computer Services will not send or request a password by email; individuals should not respond to such requests.
    2. Passwords must never be written down or stored electronically without encryption.
    3. Passwords must not be revealed in email, chat, or other electronic communication.
    4. Passwords must not be revealed on questionnaires or security forms.
    5. Vendor password sharing must be approved by Network and Computer Services.
    6. Network and Computer Services may require more restrictive policy standards as circumstances require.
    7. If someone demands a password, individuals should refer them to this policy and direct them to Network and Computer Services.
  6. If an account or password compromise is suspected, the incident must be immediately reported to Network and Computer Services.

Responsible Administrator

The Vice President for Finance and Administration, or designee, is responsible for the annual and ad hoc review of this policy and its procedures. The University President is responsible for formal policy approval.

Source and Revision History

Approved by President on 1/12/2022; Reviewed 2022/12/05; Reviewed 2024/12/03