All passwords, including initial and/or temporary passwords, must be constructed and implemented according to the following (District/Organization) rules:
- Must meet all the requirements established in the (District/Organization) Authentication Standard, including minimum length, complexity and rotation requirements.
- Must not be easily tied back to the account owner by using things like: user name, social security number, nickname, relative’s names, birth date, etc.
- Should not be the same passwords as used for non-business purposes.
- change to a strong password
- require the user to change password at first login.
Remote Access
- All remote access connections to the (District/Organization) networks will be made through the approved remote access methods employing data encryption and multi-factor authentication.
- Remote users may connect to the (District/Organization) networks only after formal approval by the requestor’s manager or (District/Organization) Management.
- The ability to print or copy confidential information remotely must be disabled.
- Users granted remote access privileges must be given remote access instructions and responsibilities.
- Remote access to Information Resources must be logged.
- Remote sessions must be terminated after a defined period of inactivity.
- A secure connection to another private network is prohibited while connected to the (District/Organization) network unless approved in advance by (District/Organization) IT management.
- Non-(District/Organization) computer systems that require network connectivity must conform to all applicable (District/Organization) IT standards and must not be connected without prior written authorization from IT Management.
- Remote maintenance of organizational assets must be approved, logged, and performed in a manner that prevents unauthorized access.
Vendor Access
- Vendor access must be uniquely identifiable. and comply with all existing (District/Organization) policies.
- External vendor access activity must be monitored.
- All vendor maintenance equipment on the (District/Organization) network that connects to the outside world via the network, telephone line, or leased line, and all (District/Organization) Information Resource vendor accounts will remain disabled except when in use for authorized maintenance.
Definitions
See Appendix A: Definitions
References
- ISO 27002: 6, 7, 8, 9, 12, 15
- NIST CSF: PR.AC, PR.IP, PR.MA, PR.PT, DE.CM
- (District/Organization) Information Classification and Handling Policy
- (District/Organization) Disaster Recovery Policy
Waivers
Waivers from certain policy provisions may be sought following the (District/Organization) Waiver Process.
Enforcement
Personnel found to have violated this policy may be subject to disciplinary action, up to and including termination of employment, and related civil or criminal penalties.
Any vendor, consultant, or contractor found to have violated this policy may be subject to sanctions up to and including removal of access rights, termination of contract(s), and related civil or criminal penalties.
Thanks! Your download is ready.