Enterprise password management policy: Finding the balance

Enterprise password management policy: Finding the balance

Users in our enterprise seem to constantly create weak passwords. When we tried to implement a stronger password system (requiring numbers, symbols and letters in a mixed configuration), our help desk was overwhelmed with forgotten password requests, and users began taping passwords to their monitors or under their keyboards. Is there a happy medium between the weak passwords that employees can remember and the strong ones that potential hackers could find?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

An enterprise password management policy should not be driven by help desk volume but by business risk appetite. How concerned is the company that accounts may be compromised? Based on the current complexities and lock-out values, how many days would it take for someone to compromise an account by automated means? How often are users required to change their passwords? All these questions should ultimately be answered based on the organization's risk posture and security policy.

That said, also consider the risk associated with sticky notes on monitors. Are walkthroughs conducted periodically to make sure classified data (such as a password) isn't left on a desk? Are there any awareness programs to educate the employees about social engineering threats?

Only the company can answer the question of how complex passwords should be, and the first step is to make sure there is a documented password management policy. The information security group should come up with one soon. The questions I asked above should be a good start to determine what that policy should be. But generally speaking, a password policy should minimally consist of the following key controls:

  • Minimum password length.
  • Specific character content, such as upper and lower case, numerals or special characters.
  • A time-table for changing passwords.
  • The number of times a bad password can be input before the account is locked by the system.
  • The number of iterations before a user can reuse a password, which prevents users from alternating back and forth between two passwords.

For more information:

This was first published in May 2009