From: <Saved by Windows Internet Explorer 7>
Subject: Standards: Password Standards - uncontrolled copy if printed
Date: Tue, 11 Mar 2008 10:23:49 -0400
MIME-Version: 1.0
Content-Type: multipart/related;
	type="text/html";
	boundary="----=_NextPart_000_0000_01C88361.FEEB29B0"
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

This is a multi-part message in MIME format.

------=_NextPart_000_0000_01C88361.FEEB29B0
Content-Type: text/html;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
Content-Location: http://file-cs1.lcc.edu/tutor11ihtml/REFL8011.htm

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML lang=3Den dir=3Dltr><HEAD><TITLE>Standards: Password Standards - =
uncontrolled copy if printed</TITLE><!-- $Header$ -->
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1252">
<META content=3Dfnd name=3DTutor_Directory><LINK=20
href=3D"http://file-cs1.lcc.edu/tutor11ihtml/tutor.css" =
rel=3Dstylesheet>
<META content=3D"MSHTML 6.00.6000.16608" name=3DGENERATOR></HEAD>
<BODY><A name=3DREFL8011></A>
<P class=3DPAGETITLE><A name=3DZZZ_TUT_0></A><FONT face=3D"Times New =
Roman"=20
size=3D3></FONT>Standards:&nbsp; Password Standards</P>
<DIV class=3DLABELTEXT>
<FORM name=3Dqlinkform action=3D"" method=3Dget><LABEL for=3Dql>Quick =
Link</LABEL>=20
<SELECT id=3Dql=20
onchange=3Dlocation=3Dqlinkform.qlink.options[qlink.selectedIndex].value;=
=20
  name=3Dqlink> <OPTION value=3D#ZZZ_TUT_0 selected>Standards: Password=20
  Standards</OPTION> <OPTION =
value=3D#ZZZ_TUT_1>&nbsp;&nbsp;Distribution</OPTION>=20
  <OPTION value=3D#ZZZ_TUT_2>&nbsp;&nbsp;Ownership</OPTION> <OPTION=20
  value=3D#ZZZ_TUT_3>&nbsp;&nbsp;Choosing a Good Password</OPTION> =
<OPTION=20
  value=3D#ZZZ_TUT_4>&nbsp;&nbsp;Avoiding a Bad Password</OPTION> =
<OPTION=20
  value=3D#ZZZ_TUT_5>&nbsp;&nbsp;Here is a List of =
"Don'ts":</OPTION></SELECT> <INPUT =
onclick=3Dlocation=3Dqlinkform.qlink.options[qlink.selectedIndex].value; =
type=3Dbutton value=3DGo>=20
</FORM></DIV>
<P class=3DSECTIONTITLE><A name=3DZZZ_TUT_1></A><FONT face=3D"Times New =
Roman"=20
size=3D3></FONT>Distribution</P>
<P class=3DBODYTEXT>Employee</P>
<P class=3DBODYTEXT>Employee Finance</P>
<P class=3DBODYTEXT>Employee Human Resources</P>
<P class=3DBODYTEXT>Employee iSupport</P>
<P class=3DBODYTEXT>Employee <ST1:PLACENAME>Star</ST1:PLACENAME>=20
<ST1:PLACETYPE>Port</ST1:PLACETYPE></P>
<P class=3DBODYTEXT>Employee Technical</P>
<P class=3DSECTIONTITLE><A name=3DZZZ_TUT_2></A><FONT face=3D"Times New =
Roman"=20
size=3D3></FONT>Ownership</P>
<P class=3DBODYTEXT>The Information Security Director <A=20
href=3D"mailto:bennetc@lcc.edu?Subject=3DStandards:%20%20Password%20Stand=
ards%20REFL8011">&lt;e-mail&gt;</A>=20
is responsible for ensuring that this document is necessary and that it =
reflects=20
actual practice.</P>
<P class=3DBODYTEXT>Picking a new password requires more thought these =
days as=20
more powerful programs to break-in are being developed all the =
time.&nbsp; Your=20
Single sign-on password needs to be a strong password because it =
protects much=20
of your information.&nbsp; Following are guidelines and best practices =
for=20
selecting and protecting your password.&nbsp; LCC=92s password standards =
are that=20
passwords should be a minimum of 8 characters with at least 1 alphabetic =

character and 1 numeric character.&nbsp; The password should be changed =
often=20
and should never be given to friends, family or co-workers.</P>
<P class=3DSECTIONTITLE><A name=3DZZZ_TUT_3></A><FONT face=3D"Times New =
Roman"=20
size=3D3></FONT>Choosing a Good Password</P>
<P class=3DBODYTEXT>Strong passwords have the following characteristics: =
</P>
<UL class=3DLISTBULLET>
  <LI>Contain both upper and lower case characters (e.g., a-z, A-Z)=20
  <LI>Have digits and punctuation characters as well as letters e.g., =
0-9,=20
  !@#$%^&amp;*()_+|~-=3D\`{}[]:";'&lt;&gt;?,./) <BR><B>Note:</B>Not all =
LCC=20
  systems accept all these characters.&nbsp; If you find that your new =
password=20
  does not work, you may need to remove the punctuation, or replace it =
with=20
  something else.=20
  <LI>Are at least eight alphanumeric characters long.=20
  <LI>Are not words in any language, slang, dialect, jargon, etc.=20
  <LI>Are not based on personal information, names of family, etc.=20
  <LI>Passwords should never be written down or stored on-line. Try to =
create=20
  passwords that can be easily remembered. One way to do this is create =
a=20
  password based on a song title, affirmation, or other phrase. For =
example, the=20
  phrase might be: "This May Be One Way To Remember" and the password =
could be:=20
  "TmB1w2R!" or "Tmb1W&gt;r~" or some other variation. </LI></UL>
<P class=3DSECTIONTITLE><A name=3DZZZ_TUT_4></A><FONT face=3D"Times New =
Roman"=20
size=3D3></FONT>Avoiding a Bad Password</P>
<P class=3DBODYTEXT>Poor, weak passwords have the following =
characteristics: </P>
<UL class=3DLISTBULLET>
  <LI>The password contains less than eight characters=20
  <LI>The password is a word found in a dictionary (English or foreign)=20
  <LI>The password is a common usage word such as: </LI></UL>
<UL class=3DNOTELIST1>
  <LI>Names of family, pets, friends, co-workers, fantasy characters, =
etc.=20
  <LI>Computer terms and names, commands, sites, companies, hardware, =
software.=20
  <LI>The words "Lansing=94, =93Community=94, =93College", "redwings", =
"Michigan=94,=20
  =93State" or any derivation.=20
  <LI>Birthdays and other personal information such as addresses and =
phone=20
  numbers.=20
  <LI>Word or number patterns like aaabbb, qwerty, zyxwvuts, 123321, =
etc.=20
  <LI>Any of the above spelled backwards.=20
  <LI>Any of the above preceded or followed by a digit (e.g., secret1, =
1secret)=20
  </LI></UL>
<P class=3DBODYTEXT>Do not use the same password for=20
<ST1:PLACE><ST1:PLACENAME>Lansing</ST1:PLACENAME> =
<ST1:PLACETYPE>Community=20
College</ST1:PLACETYPE></ST1:PLACE> accounts as for other=20
<ST1:PLACE><ST1:PLACENAME>non-Lansing</ST1:PLACENAME> =
<ST1:PLACETYPE>Community=20
College</ST1:PLACETYPE></ST1:PLACE> access (e.g., personal ISP account, =
option=20
trading, benefits, etc.). Where possible, don't use the same password =
for=20
various <ST1:PLACE><ST1:PLACENAME>Lansing</ST1:PLACENAME>=20
<ST1:PLACETYPE>Community College</ST1:PLACETYPE></ST1:PLACE> access =
needs. For=20
example, select one password for the Departmental systems and a separate =

password for Oracle Star Port Single Sign-On systems.&nbsp; Do not share =

<ST1:PLACE><ST1:PLACENAME>Lansing</ST1:PLACENAME> =
<ST1:PLACETYPE>Community=20
College</ST1:PLACETYPE></ST1:PLACE> passwords with anyone, including=20
administrative assistants or secretaries. All passwords are to be =
treated as=20
sensitive, confidential =
<ST1:PLACE><ST1:PLACENAME>Lansing</ST1:PLACENAME>=20
<ST1:PLACETYPE>Community College</ST1:PLACETYPE></ST1:PLACE> =
information.&nbsp;=20
LCC=92s use of Single Sign-On technology requires greater protection by =
the user=20
of their password, as that single password will allow access to many=20
systems.</P>
<P class=3DSECTIONTITLE><A name=3DZZZ_TUT_5></A><FONT face=3D"Times New =
Roman"=20
size=3D3></FONT>Here is a List of "Don'ts": </P>
<UL class=3DLISTBULLET>
  <LI>Don't reveal a password over the phone to ANYONE=20
  <LI>Don't reveal a password in an email message=20
  <LI>Don't reveal a password to the boss=20
  <LI>Don't talk about a password in front of others=20
  <LI>Don't hint at the format of a password (e.g., "my family name")=20
  <LI>Don't reveal a password on questionnaires or security forms=20
  <LI>Don't share a password with family members=20
  <LI>Don't reveal a password to co-workers while on vacation </LI></UL>
<P class=3DBODYTEXT>If someone demands a password, have them call the =
ISCD Help=20
desk at (517) 483-5221.</P>
<P class=3DBODYTEXT>Passwords should only be entered on known password =
entry=20
screens.&nbsp; Become familiar with the screen that you enter a password =
into=20
and verify that you are not using a fake login screen.&nbsp; Verify that =
your=20
TUID single sign-on password is only entered within a web page that =
comes from=20
=91https://bonnie.lcc.edu:4443/pls/orasso/orasso.lccp_login.home=92.&nbsp=
; </P>
<P class=3DBODYTEXT>It is best practice to not use the "Remember =
Password" feature=20
of applications, especially for shared or public computers (e.g., =
Eudora,=20
Outlook, and Netscape Messenger).</P>
<P class=3DBODYTEXT>Again, do not write passwords down and store them =
anywhere in=20
your office. Do not store passwords in a file on ANY computer system =
(including=20
Palm Pilots or similar devices) without encryption or separate password=20
protection.</P>
<P class=3DBODYTEXT>Change passwords at least once every six months =
(except=20
system-level passwords which must be changed quarterly). The recommended =
change=20
interval is every four months. </P>
<P class=3DBODYTEXT>If an account or password is suspected to have been=20
compromised, report the incident to abuse@lcc.edu and change all =
passwords. </P>
<P class=3DEFFECTREV>Effective: 11/18/03</P>
<P class=3DEFFECTREV>Revision: 1</P>
<HR>

<P class=3DCOPYRIGHT>Copyright =A9 2004 Lansing Community College. All =
rights=20
reserved.</P>
<P class=3DCOPYRIGHT>Oracle=AE Tutor&nbsp;&nbsp;&nbsp;Copyright =A9 =
1997, 2003, <A=20
href=3D"http://www.oracle.com/">Oracle Corporation</A>. All rights=20
reserved.</P></BODY></HTML>

------=_NextPart_000_0000_01C88361.FEEB29B0
Content-Type: text/css;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Location: http://file-cs1.lcc.edu/tutor11ihtml/tutor.css

P {
	FONT-SIZE: small; MARGIN-LEFT: 0.1in; COLOR: black; FONT-FAMILY: Arial, =
Helvetica, Geneva, sans-serif
}
A {
	FONT-FAMILY: Arial, Helvetica, Geneva, sans-serif
}
A:link {
	COLOR: #663300
}
A:active {
	COLOR: #336699
}
A:visited {
	COLOR: #996633
}
UL {
	FONT-SIZE: small; FONT-FAMILY: Arial, Helvetica, Geneva, sans-serif
}
OL {
	FONT-SIZE: small; FONT-FAMILY: Arial, Helvetica, Geneva, sans-serif
}
P.ACTOR {
	BORDER-RIGHT: 2pt; BORDER-TOP: 2pt; FONT-WEIGHT: bold; FONT-SIZE: =
medium; BORDER-LEFT: 2pt; COLOR: #336699; BORDER-BOTTOM: 2pt; =
LETTER-SPACING: 0.1em; BACKGROUND-COLOR: #cccccc; TEXT-ALIGN: center
}
P.BOXTEXT {
	BORDER-RIGHT: 2pt; BORDER-TOP: 2pt; PADDING-LEFT: 0.15in; FONT-SIZE: =
small; MARGIN-LEFT: 0.5in; BORDER-LEFT: 2pt; LINE-HEIGHT: 1.5; =
MARGIN-RIGHT: 1in; PADDING-TOP: 0.05in; BORDER-BOTTOM: 2pt; FONT-FAMILY: =
Lucida Sans Unicode; BACKGROUND-COLOR: #cccaaa
}
P.CHAPTERSUBTITLE {
	FONT-WEIGHT: bold; FONT-SIZE: medium; COLOR: #336699; TEXT-ALIGN: =
center
}
P.CHAPTERTITLE {
	FONT-WEIGHT: bold; FONT-SIZE: large; COLOR: #336699; TEXT-ALIGN: center
}
P.DIRECTIVE {
	FONT-WEIGHT: bold; FONT-SIZE: small; MARGIN-LEFT: 0.1in
}
P.INSTRUCTOR {
	FONT-SIZE: small; COLOR: #336699
}
P.NOTE1 {
	MARGIN-LEFT: 0.6in
}
P.NOTE2 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 0.9in
}
P.NOTE3 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 1.2in
}
.NOTELIST1 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 1in; LIST-STYLE-TYPE: circle
}
.NOTELIST2 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 1.2in; LIST-STYLE-TYPE: =
circle
}
.NOTELIST3 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 1.4in; LIST-STYLE-TYPE: =
circle
}
P.PAGETITLE {
	FONT-SIZE: large; MARGIN-LEFT: 0in; COLOR: #336699; TEXT-ALIGN: center
}
P.PAGETITLE2 {
	FONT-SIZE: large; MARGIN-LEFT: 0in; COLOR: #336699
}
P.QUALIFIER {
	FONT-WEIGHT: bold; FONT-SIZE: small; MARGIN-LEFT: 0.3in
}
P.SECTIONTITLE {
	FONT-WEIGHT: bold; FONT-SIZE: medium; MARGIN-LEFT: 0.1in; COLOR: =
#336699
}
P.SUBHEADING {
	FONT-WEIGHT: bold; FONT-SIZE: small; MARGIN-LEFT: 0.1in; COLOR: #336699
}
P.TABLE {
=09
}
P.TABLEHEADER {
	FONT-WEIGHT: bold; COLOR: #336699; TEXT-ALIGN: center
}
P.TASK1 {
	MARGIN-LEFT: 0in
}
.TASK2 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 0.4in
}
.TASK3 {
	LIST-STYLE-POSITION: outside; MARGIN-LEFT: 0.6in
}
P.COPYRIGHT {
	FONT-SIZE: x-small; COLOR: #336699; TEXT-ALIGN: center
}
P.EFFECTREV {
	FONT-STYLE: italic
}
.LISTBULLET {
	MARGIN-LEFT: 0.3in
}
.LISTNUMBER {
	MARGIN-LEFT: 0.3in
}
.LABELTEXT {
	FONT-SIZE: small; MARGIN-LEFT: 0.1in; COLOR: black; FONT-FAMILY: Arial, =
Helvetica, Geneva, sans-serif
}

------=_NextPart_000_0000_01C88361.FEEB29B0--
