Educause Security Discussion mailing list archives

Re: Password Security


From: Vicky Walker <Vwalker () UNT EDU>
Date: Tue, 23 Oct 2007 12:47:58 -0500

I agree with you.  Have you tried talking to you Internal Audit and/or legal departments?  I think they would be very 
concerned about this proposed action.  IA can be the Security team's  best friend.  We have a very good working 
relationship here at UNT!
 
vicky
 
Vicky Walker-Brooks
University of North Texas
EIS Security Team Lead
vwalker@unt
940-565-3376
 
*******************************************
Nobody, but nobody, can make it out here alone.    Maya Angelou
*******************************************


"Mclaughlin, Kevin (mclaugkl)" <mclaugkl () UCMAIL UC EDU> 10/23/2007 11:43 AM >>>
Hi All:

I am currently fighting an internal battle and wanted to do a sanity check
to see if I am being too stubborn with my stance.

Scenario:

I have a department that wants to give their employees information on
business sized cards.  There is a slot on the card for people to write down
their passwords to their payroll and annual benefits account.  The idea is
for the less computer literate staff to be able to keep these handy (in
their wallets or purses let's say) so that they can refer to them as needed.


For years we have been teaching people to not write their passwords down and
while some people may do this on their own I feel that by telling them to do
something that is so "anti-best practice" we are increasing our overall
liability if any of these accounts are breached.  Btw - I have discussed
many alternative approaches with the department - none of which they are
interested in hearing.

Thoughts?  (can be directed to me personally vs. the listserve if you
prefer)

-Kevin


Kevin L. McLaughlin
CISM, CISSP, PMP, ITIL Master Certified
Director, Information Security
University of Cincinnati
513-556-9177 (w)
513-703-3211 (m)
513-558-ISEC (department)





CONFIDENTIALITY NOTICE: This e-mail message and its content is confidential,
intended solely for the addressee, and may be legally privileged. Access to
this message and its content by any individual or entity other than those
identified in this message is unauthorized. If you are not the intended
recipient, any disclosure, copying or distribution of this e-mail may be
unlawful. Any action taken or omitted due to the content of this message is
prohibited and may be unlawful.



Current thread: