Quantcast
Channel: SANS Internet Storm Center, InfoCON: green
Viewing all articles
Browse latest Browse all 8255

Some password advice, (Sun, Sep 13th)

$
0
0

No not from me, but from the UK government.

GZ (thanks) sent a link through to this document" target="_blank">https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/458857/Password_guidance_-_simplifying_your_approach.pdfpublished by the UK government.

The document is a little bit different to many other such advise handed out by many organisationsin that it is aimed more at system administrators rather than end users. As far as the actual advise to system administrators. It is nothing too revolutionary, but then we are dealing with passwords. And there isnt anything there that most of us wouldnt agree with. It does server as a little reminder that we should all be taking some care with passwords.

The 7 tips are:">">PrioritiseAdministrators and Remote user accounts

  • Use account lockouts and protective monitoring
  • Dont store passwords as plain text
  • None are earth shattering, yet all of us know that pretty much every organisationhas users with passwords of Password123, Changeme, Welcome1 and of course Ashley Martin user favourites 123456. Numbers 1 and 7 feature in most penetration testing reports you read or write.

    So whilst these tips provided by the UK government arent new or fantastic I would encourage you to spend a few minutes reading the document and on Monday see how your organisation meets, exceeds or perhaps fails in one or more of them.

    Well be stuck with passwords for a while yet, we should at least make people work for them a bit harder.

    Cheers

    Mark H

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    Viewing all articles
    Browse latest Browse all 8255

    Trending Articles