USGS Water Resources
INTERNAL USGS ACCESS ONLY

Water Resources Discipline
ITAC Activities

From:

Terri J Moore 05/31/2005 07:17 PM

To:

GS-W ITAC

cc:

 

Subject:

Password Management Web Site

_____________________________________________

Attached is the original letter to BITSM.

Terri "TJ" Moore
Western Region Computer Specialist
U.S. Geological Survey, Water Discipline
3020 State University Drive, East, Suite 3005
Sacramento CA 95819
Ph: 916-278-9553, Fax: 916-278-9556
Mobile: 916-869-0100
email: tejmoore@usgs.gov

----- Forwarded by Terri J Moore/WRD/USGS/DOI on 05/31/2005 04:17 PM -----

From:

Terri J Moore 04/26/2005 10:30 AM

To:

Ellen T Erickson/GIO/USGS/DOI@USGS

cc:

Jeffrey D Stoner/WRD/USGS/DOI@USGS

Subject:

Password Policy

To: BITSM 25 April 2005

Cc: ITAC

From: Terri J. Moore
ITAC member

Subject: Password Policy

The Information Technology Advisory committee (ITAC), through this correspondence, is asking the BITSM office to address the issue of password management. We understand that passwords need to be controlled to maintain our computer security posture. However, because of the increased level of security of IT systems, password management has quickly become a convoluted maze of varying password requirements to access our password-based authentication to the numerous IT systems and networks. Each system has different requirements to include minimum and disallowed password content (min/max lengths and required or disallowed characters), required change frequency, protection mechanisms (must be one-way encrypted, must not be displayed when entered), and the number of unsuccessful login attempts allowed, just to name a few.

In an effort to increase the security of our network, the implementation of DOI password policy has quickly decreased the effectiveness of individuals to remember their password(s). In order to retain all of the different passwords, individuals are now writing them down regardless of management and DOI directives. The ITAC would like to see an effort to consolidate and standardize password requirements across the systems we control. As much as possible, we should strive to match the systems we do not have control of as we design the requirements for the systems we do have control of to maximize consistency. DOI’s computer password policy states a maximum password age to be set at least 90 days, although QuickTime is currently set at 60 days. The minimum and disallowed password content and required change frequency are two of the key requirements that are the most inconsistent and cause the most frustration to the user.

It would be beneficial if the BITSM office would provide guidance on the recommended hardware and software solutions for password management to the users such as KeePass and password management token technology. In addition, a website that documents the existing password requirements for each system would be useful.


Terri “TJ” Moore
Regional Computer Specialist
Water Discipline
Office of the Regional Hydrologist
tejmoore@usgs.gov
916.278.9553 Office
916.869.0100 Cell


Click on a major heading to other links!

TOP #top ITAC home /usgs/nwis/itac ITAC AIs /usgs/itac/docs/ai_history_index.html

Address questions or comments to
Marilyn Billone, mabillon@usgs.gov,
ITAC Secretary, on 703-648-5658

first go logo



URL for this document is http://water.usgs.gov//usgs/itac/minutes/atlanta_050208/050531_password_policy.html
If you have any questions or comments about this document contact ITAC Webmaster
Last modified: Tues. Feb. 17, 2004 1:49:35 EST