Frequently Asked Question

Password Policy
Last Updated a year ago

Overview

Passwords are an important aspect of computer security. They are the front line of protection for user accounts. A poorly chosen password may result in the compromise of Chroma Color Corporations entire corporate network. As such, all Chroma Color Corporation employees or consultants (including contractors and vendors with access to Chroma Color Corporation systems) are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.

Purpose

The purpose of this policy is to establish a standard for the creation of strong passwords, the protection of those passwords, and the frequency of change.

Audience

This policy applies to all personnel who have, or are responsible for, an account (or any form of access that supports or requires a password) on any system that resides at any facility, has access to the network, or stores any non-public Chroma Color Corporation information.

Policy Detail

User Network Passwords

  • Passwords for network access must be implemented according to the following guidelines:
    • Passwords must be changed every 90 days
    • Passwords must adhere to a minimum length of 10 characters
    • Passwords must enforce complexity and contain upper case, lower case number and special characters (!@#$%^&*_+=?/~’;’,<>|\).
  • Passwords must not be easily tied back to the account owner such as:
    • username, social security number, nickname, relative’s names, birth date, etc.
  • Passwords cannot be reused for 3 years

Password Protection

  • The same password must not be used for multiple accounts.
  • Passwords must not be shared with anyone. All passwords are to be treated as sensitive, confidential Chroma Colors Corporation information.
  • Stored passwords must be encrypted.
  • Passwords must not be inserted in e-mail messages or other forms of electronic communication.
  • Passwords must not be revealed over the phone to anyone.
  • Passwords must not be revealed on questionnaires or security forms.
  • Chroma Colors Corporation passwords must not be shared with anyone, including co-workers, managers, or family members, while on vacation.
  • Passwords must not be written down and stored anywhere in any office. Passwords must not be stored in a file on a computer system or mobile device (phone, tablet) without encryption.
  • If the security of an account is in question, the password must be changed immediately. In the event passwords are found or discovered, the following steps must be taken:
    • Take control of the passwords and protect them
    • Report the discovery to IT at [email protected]
  • PCs must not be left unattended without enabling a password-protected screensaver or logging off the device.

Enforcement

  • Account Lockout: Repeated failed login attempts will result in account lockout.
  • Password Reset: IT staff will assist with password resets, but users are responsible for creating strong passwords.
  • Security Awareness Training: Regular security awareness training will be provided to reinforce password best practices.

Violation of this policy may result in disciplinary action.

By adhering to this password policy, we can significantly reduce the risk of unauthorized access to our systems and protect our sensitive information.

Loading ...