Educause Security Discussion mailing list archives

Passwords


From: "Madl, Michael" <michael.madl () INDWES EDU>
Date: Thu, 15 Feb 2018 13:53:06 +0000

Morning,

Have a few questions on how your institution is managing IT passwords.  These would include system admin accounts, 
service accounts with elevated access and other critical accounts.


*         Are you utilizing a centralized password manager?  What is it? On-premise/Cloud?

o   If your answer is cloud what is your comfort level on uploading them to a provider?

*         If not centralized how are passwords managed in your decentralized environment?

*         How is access controlled to passwords?

o   Is there one person who has the keys to the kingdom? [CISO/ISO/CIO] or are your passwords accessed only as needed 
by defined roles?  Does each area have a 'password manager'?

Thanks in advance for you input and experience.



MICHAEL MADL
INFORMATION SECURITY OFFICER
UNIVERSITY INFORMATION TECHNOLOGY

INDIANA WESLEYAN UNIVERSITY
4201 SOUTH WASHINGTON STREET
MARION, IN 46953

765.677.2688   |   765.677.2020 FAX
michael.madl () indwes edu<mailto:mike.madl () indwes edu>

  [iwu]

CONFIDENTIALITY NOTICE: This email, including applicable attachments, may include legally protected information.  If 
you are not the intended recipient of this message, you may not disclose, print, copy, save, or disseminate this 
information. If you have received this email in error, please notify the sender by replying to this message and 
immediately delete this message.


Current thread: