Jump to content

Recommended Posts

Posted

Hi All,

 

I'm fairly new to a School and I've recently discovered a they dont have a password policy, so essentially staff can have a 4 letter password forever without the need to change it etc etc etc.

 

I've created a change control and pushed it through SMT but there's been uproar from some staff who stay teachers so say its "unworkable" for teaching staff who dont have phones to call IT with etc. Which leads me onto my question, what policies are at your School and how do you get on? My proposal was:

 

A) Set a password that has a minimum length of 8 characters.

B) Change their password every 42 days.

C) Meet certain password complexity requirements – a password will need to contain three of the following four categories in order to be valid.

D) Use at least 24 unique passwords – 24 unique new passwords must be used before an old password can be reused.

E) Lock-out period after 3 consecutive uses of the wrong password – if a user enters a password incorrectly 3 times, the account will be locked out for 15 minutes.

 

 

Thanks

Posted

We've got two policies in place, one for staff who want to use our RDS system and one for everyone else. The general policy is:

 

*At least 6 characters

*At least one upper case, one lower case and one number

*Lockout after 3 failed attempts

*Currently no expiry but we may change that in the next few months to 60 days or something

*Can't contain the users name

 

Our Remote Access policy is a lot more convoluted and has things like not being able to use 3 consecutive characters in different passwords. We've also got an alternate method which uses pass phrases, which require at least 15 characters, at least 2 spaces and at least one upper case letter. Most staff choose the pass phrase option as it's less complicated than all the complex rules we've got in place for the password option.

Posted

IMO D is a really bad idea. I've worked in places where this had been implemented and leads to hostility amongst users, who will make your life hell, unless you allow for example Password1, followed by Password2, Password3, etc.

 

Also, 42 days is probably too soon. We have ours set to 100 days.

 

Our policy is :

  • 8 chars or more
  • can't contain your name or user id
  • at least one character from 3 of the 4 categories - upper case, lower case, number, symbol
  • 3 unique passwords
  • 100 days expiry
  • lockout after 3 tries

Posted

Off the top of my head we have...

 

* 8 characters - Google requirement

* Change every 90 days, one a term

* 3 unique passwords

* lock out for 5 min after 5 attempts

Posted
Hi All,

 

I'm fairly new to a School and I've recently discovered a they dont have a password policy, so essentially staff can have a 4 letter password forever without the need to change it etc etc etc.

 

This is absolutely appalling - Staff need to appreciate that they have access to sensitive information about both the organisation and, more importantly, all kinds of personal information about students, some of which may well be vulnerable.

 

I've created a change control and pushed it through SMT but there's been uproar from some staff who stay teachers so say its "unworkable" for teaching staff who dont have phones to call IT with etc. Which leads me onto my question, what policies are at your School and how do you get on?

 

I'm not sure why "don't have phones to call IT with" is relevant?

It's perfectly 'workable' to have a password policy - we enforce a minimum of six letters, a change time of 120 days, and a 10 password history.

 

A) Set a password that has a minimum length of 8 characters.

B) Change their password every 42 days.

C) Meet certain password complexity requirements – a password will need to contain three of the following four categories in order to be valid.

D) Use at least 24 unique passwords – 24 unique new passwords must be used before an old password can be reused.

E) Lock-out period after 3 consecutive uses of the wrong password – if a user enters a password incorrectly 3 times, the account will be locked out for 15 minutes.

 

Ok, some of these I would regard as a little stringent for some of the more computer-phobic people out there. What is the precise business requirement that is being served by using these choices instead of the ones I said are used at my place? (Not that I'm saying "I'm right and you're wrong" - our settings are the result of compromises between what I'd like to do and what staff can reliably handle, and I'm wondering if you've turned on all the features because you can, and a slight softening of your approach may take most of the sting out of the criticisms of your staff).

Posted (edited)

Ours is below. We had some teething problems when it was introduced, but we don't have much of a problem now. We have a few members of staff who find it impossible to remember passwords but that's about it. Our rules are based on what was advised to me by audit at my last school.

 

[h=2]Staff password policy[/h]Password complexity is enabled, meaning:

 

· Passwords must be at least 8 characters long

· Must contain at least 1 uppercase letter

· Must contain at least 1 lowercase letter

· Must contain at least 1 numerical digit

· Cannot be any of the last 24 passwords used

· Cannot contain any part of the user’s name or username

 

· Passwords must change every 45 days

 

· Accounts become locked out after 10 invalid logon attempts, automatically resetting 60 minutes after latest failed attempt

· Passwords are not stored in a “reversible” format, so cannot be recovered, only reset

 

[h=2]Pupil password policy[/h]Password complexity is enabled, meaning:

 

· Passwords must be at least 4 characters long

· Accounts become locked out after 10 invalid logon attempt, automatically resetting 30 minutes after latest failed attempt

· Passwords are not stored in a “reversible” format, so cannot be recovered, only reset

Edited by localzuk
Posted

For staff:

 

Minimum Length: 6

Passwords remembered: 5

Must meet complexity requirements: Yes

Minimum Password Age: 3

Maximum Password Age: 90

Failed Logon Attemps Allowed: 5

 

Pretty standard.

Posted
My proposal was:

We have much the same as AD policy, but I'm happy to run them a lot longer than 42 days in exchange for more entropy.

 

We also have some policy in the AUP, such as not sharing passwords or allowing students access to accounts used by teachers. We still get the occasional gaff - teachers sending their laptops to us in the care of a student with the password written on a post it and stuck to the screen.

Posted
Thanks for all the replies, its really appreciated. I think I'll look to extend the password change to possibly 80-90 days for try and fit better with terms. Its good to know we are unusual not having a policy as this should help my argument.
Posted

Ours is:

8 characters

At least one capital letter

At least one number

Cannot use last 3 passwords (I fought this but this was the best I could get)

Change once a term

Posted

ICT Staff - 11 characters, complex, yearly expiry

Senior school and staff is 11 characters, complex, no expiration.

Primary - 8 characters, simple (on promotion to senior school password is set to expire so they choose a new one)

Infants - none (restricted logon to that part of the school)

  • 1 month later...
Posted

Just had an IT Security Audit last month.

 

Our staff policy was:

6 Characters

Complex (3 from 4)

No re-use in 12

30 attempts before lockout

30 minute lockout period

1 Day minimum age

Expires every 30 days

 

Yes, staff moaned about the complexity initially, but they're essentially fine about it now.

 

The auditor suggested we reduce the lockout threshold down to 5 - ie 5 failed attempts will lock the account. Otherwise a hacker (or bot) can try one a minute every minute forever.

 

We did this, but we're getting calls about lockouts at least once per hour. Now we don't believe this is users failing their passwords, so we're now looking into what is causing it - many of them use iPads, but it's happening too often to be staff that have changed their AD password but not updated their mail client, for example.

 

Temporarily raised it back to 10 attempts whilst I investigate. (Just before going to Governors tonight to present the results of the IT Audit which did say 'we have met this objective by....' but is now a bag of lies!)

Posted
...getting calls about lockouts at least once per hour. Now we don't believe this is users failing their passwords, so we're now looking into what is causing it ...

 

We had that when we enforced our lockout and complexity policy, turn out to be a few teachers had joined their phones to the Wireless via RADIUS and forgot, phone was attempting to authenticate every few minutes, failing due to a password change and trying again when it woke up.

Posted
We had that when we enforced our lockout and complexity policy, turn out to be a few teachers had joined their phones to the Wireless via RADIUS and forgot, phone was attempting to authenticate every few minutes, failing due to a password change and trying again when it woke up.

 

Interesting...

 

We tried Radius but turned it off cos it didn't work with our setup. However we do use other mechanisms which might possibly have same effect - I'll have a think.

Posted
We had that when we enforced our lockout and complexity policy, turn out to be a few teachers had joined their phones to the Wireless via RADIUS and forgot, phone was attempting to authenticate every few minutes, failing due to a password change and trying again when it woke up.

 

Yes we suffered with that too

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...