Tech Guides :: Securing Confidential Information
Password Protection
Information Technology Services (ITS) enforces strong passwords (length, complexity), password ageing, and log-on multiple-attempt limits for central computing servers and access to the Common Management System. ITS password requirements are posted on its website at: http://www.humboldt.edu/~its/techguides/security/passwords.shtml. Additionally,
1. User systems in general, and servers in particular, should be protected similarly.
2. User systems and servers storing personally identifiable and/or other confidential information must be protected similarly.
3. If passwords are stored on a system, they should be encrypted with a strong encryption method. Microsoft Office encryption is not acceptable.
4. Passwords for accessing central servers maintained by ITS are not to be stored on user systems, either in files or hard-coded into scripts, without first contacting the ISO. The ISO will initiate a technical and security review of the user's need to store central server passwords on his or her system.
5. Users must use SFTP and SSH because FTP and Telnet pass clear text passwords.
6. Passwords may not be shared unless authorized by the user's immediate supervisor in writing.
Contacting the Campus Information Security Officer
The Campus Information Security Officer can be reached at (707) 826-3815 or security@humboldt.edu.
Endorsed by the Information Technology Council, April 11, 2006
