Home > Security Tips > Weekly Security Planner > Week 2: Passwords -- Updating, selecting and recording user and administrative passwords
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEEKLY SECURITY PLANNER

Week 2: Passwords -- Updating, selecting and recording user and administrative passwords


Shelley Bard, CISSP
12.12.2003
Rating: -4.10- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In an effort to help busy security managers, CISSP Shelley Bard's weekly column builds upon the concept of the perpetual calendar, offering a schedule of reminders for a proactive, strategic security plan. Also visit our archive of previous columns.

What
Regular audits to make sure passwords comply with security policy.

When
Typically once every quarter or six months, depending on your level of CIA2.

Why
Why are eight-character passwords recommended? Using a very fast machine, passwords six characters or less can be matched in less than two days. Seven-character passwords can be matched in four months. By the time an eight-character password could be cracked, you should have changed the password to a new eight-letter string, thereby protecting your account.

Strategic tools
For changing users' passwords, use your operating system's configurable notification countdown schedule to inform users that their password will expire in XX days. Force the use of mixed case alphanumeric passwords. Suggest strategies, such as using uncommon phrases and creative use of number-letter substitution so they don't write them down.

Change all of the administrative passwords regularly, as well as every time an admin leaves, not only for the primary systems, but for the back-ups as well. Don't forget about your hot/warm/cold site backup. Record passwords in a secure location. Use the following password worksheet to help account for your admin passwords.

Changing device passwords is another issue. What if you have 500 routers in your architecture? Then you should also have an administrative tool to push out configurations and passwords. The time and effort you save over doing it manually will be more than worth the expense. A relatively small footprint of exposure means you can consider changing these passwords only once a year during a time of decreased system traffic to minimize any issues resulting from a rollover.

In any case, make sure all accounts have a strong password -- no nulls, defaults or guest accounts -- and that the password-check mechanism is protected.

Finally, there's system password handling. Passwords are passed by the system through a variety of means – clear text, automatic updates, hard-coded or encrypted/hidden in machine code. You need to know which do what on your system and secure them accordingly. Do you have any default passwords shipped with your system? Change those as well.

More information
Query the Internet for such terms as "password selection strategies" and "choosing a good password." Consider running a password cracker routine against the password files to gauge the success of your users' selection strategies. Good ones include LC4 and John The Ripper.

Last week: The security manager's daily checklist
Next week: Restore a back-up tape and recover usable data

About the author
Shelley Bard, CISSP, is a senior security network engineer with Verizon Federal Network Systems (FNS). An infosecurity professional for 17 years, Bard has briefed and written infosecurity assessments and technical reports for the White House and Department of Defense, special interest groups, industry and academia. Please e-mail any comments to securityplanner@infosecuritymag.com.

Opinions expressed in this column are those of Shelley Bard and don't necessarily reflect those of Verizon FNS.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Weekly Security Planner
Weekly Security Planner: April
Weekly Security Planner: March
Weekly Security Planner: January
Weekly Security Planner: February
Weekly Security Planner: December
Weekly Security Planner: November
Weekly Security Planner: September
Weekly Security Planner: August
Weekly Security Planner: October
Weekly Security Planner: July

Security Management
Smart shopper's guide to correlation tools
What's your infosec IQ?
Countdown begins for Mydoom DDoS attacks
Hackers scanning for ports opened by Mydoom
National cybersecurity alert system launched
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes
SSL VPNs stealing IPSec's thunder
Expert sheds light on Wi-Fi liability issues
Security insurance may be a smart policy for some

Security Policy & Infrastructure
Tier-1 policies overview, part four: Procurement and Contracts, Records Management and Asset Classification Policies
Tier-1 policies overview, part three: Corporate Communications, Work Place Security and Business Continuity Plan Policies
Action-forcing mechanisms encourage policy compliance
Presentation: Essential strategies for policy development
Developing security policies
Best practices: E-mail security policies
What constitutes acceptable use?
Infosec Know IT All Trivia: Policy management
Terminating a system administrator
Security policies should work from home too!

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts