Small Business Information
Security: The Fundamentals
Derek Davis
NISTIR 7621
Small Business Information
Security: Password Management
Policy
Derek Davis
Overview of Computer
Security CSCI 501
School of Engineering
Center for Cyber
Security Mr. Jason Dion
Liberty University
Lynchburg, VA 24515
October 2016
Acknowledgements
The Author, Derek Davis, wishes to thank Mr. Dixon and the class of CSCI 501 for sharing in this
experience of introducing cyber security. This course has provided a great deal of information that will be
beneficial to the advancement into this career. Special thanks to the classmates who will review this
document and provide input on helping make it better.
Table of Contents
1. Introduction
Purpose
Scope
2. Specific Areas of Concern
Necessity for protection of all employee accounts
The “absolutely necessary” actions that a small business must take to ensure that
access to information, employee accounts, and data from the server are safeguarded
through proper password management
Requirements for all employees to have individual employee accounts
Realized threat and hazards that will result from lack of proper password management
Proper techniques for utilizing safe and unique passwords to ensure that passwords are
not compromised
Drafting and utilizing software that will require frequent password changes to every
employee account
Controlling access to computers, and network components
Issuing guidelines and conducting training on improper password safeguard and usage
3. Highly Recommended Practices
Security concerns resulting from failing to log off device
Security concerns that stem from sharing or allowing others to use your password
Security concerns from utilizing passwords that fail to meet the minimum strength level
standard
Security concerns with writing down passwords to retain for record
Security concerns with using the same password for company access and accounts
that are used for personal accounts
Employees that have system level privilege membership must not use the same password
for multiple levels of access
Employees must not use the “remember password” feature for any system or software on
the network
Password guessing and cracking procedures
4. Policy Compliance
Information Security teams will verify compliance to this policy
Exceptions to this policy
Non-Compliance
Overview
As the world races towards an era of total technological dependence, it is imperative that
information is secure while employees utilize any network. One of the most fundamental
vulnerabilities center around employee errors and mistakes. A major area of concern is employee
password management. Small businesses like Liberty Beverages are at an alarming disadvantage
when compared to large businesses because large businesses have become less desirable to
attackers with malicious intent and thus, it has become increasingly more important for Liberty
Beverage to reinforce proper password management in order to ensure that the network, servers,
systems, hardware, and software is safeguarded from attack.
1. INTRODUCTION
While passwords play a major role in safeguarding data and content on professional and
personal profiles and accounts, it is common for employees to become incredibly careless
with their management of passwords. This can pose a great threat to Liberty Beverage
and its subsidiaries. Routinely, for personal accounts, employees tend to use common
words as a password; share their passwords with individuals that they believe they can
trust; or even fail to log off after leaving a station, providing unobstructed access to the
device, account, or profile. While the potential risk for damage may be minimal for those
personal accounts due to the lack of importance of information therein, this is something
Liberty Beverage cannot allow. The information accessed throughout Liberty Beverage’s
network is intended for the use of Liberty Beverage employees and thus lack of care in
the password management department is of the utmost importance. Information that can
be accessed throughout the network can pose critical damage to the Liberty Beverage’s
revenue through providing information to the company’s competitors that would impede
competitive efforts, to the employees and customers through providing personal
identification information, and to Liberty Beverage reputation. Employees may find that
this level of attention for password management procedures is excessive, but the cost, and
therefore the importance, of repairing damage caused by a lack of attention to proper
password management exceeds the value of any amount of time and effort to ensure
employees are properly educated and trained on proper password management. The
purpose of this policy is to ensure that Liberty Beverage does not have to maintain
responsibility of any breech that occurs as a result of employee actions in a failure to
maintain proper password management. This policy applies to every employee of Liberty
Beverage and its subsidiaries.
2. Specific Areas of Concern
Because access to the information accessible through Liberty Beverage network is
limited to employees of Liberty Beverage only, it is vital that all employees maintain a
level of caution as it relates to accessing this information and the credentials assigned for
this access.
Proper password management is vital to any business’s success. The information that
can be accessed once a employee inputs necessary passwords is limitless provided the
adequate employee system level privileges. It is “absolutely necessary” that Liberty
Beverage conducts periodic training on the information herein, and ensure that all
employees adhere to the policy and procedures outlined herein to ensure that access
to information, employee accounts, and data from the server are properly safeguarded
Once an employee has completed orientation with the Human Resources Department
(HR) he or she will have 48 hours to activate the previously authenticated employee
account and validate the personal password to that account. Every employee of Liberty
Beverage will utilize and maintain that account until the termination of the employee’s
employment. Every employee will access the network through company systems using
only their assigned credentials.
Lack of proper password management can result in a beech of the Liberty Beverage
network. This breech can expose data that makes the company’s product competitive
against competing businesses. As a result, the products that Liberty Beverage provides
can be devalued and the revenue for these products will dissolve throwing the business
into a financial crisis. In addition, any breech exposes personal identification
information of all employees and customers associated with Liberty Beverage.
It is important that all passwords for accounts and profiles are properly maintained and
follow the strict guidelines outlined in this policy. Passwords are to remain personal and
are not to be shared with anyone in any form or through any mean of communication. In
addition, all passwords are to contain a minimum of 10 characters with any combination
of alphanumeric characters and non-alphanumeric characters. Passwords are not to use
two identical characters next to one another anywhere within the password and are not to
contain any personally identifiable information such as names. Employees will be
required to change passwords every 6 months and cannot use the same password two (2)
times in a row to ensure that Liberty Beverage profiles and accounts are properly
secured.
Information Security teams will implement software that will notify all employees that
passwords are to be changed every 6 months. This software will send email notifications
each week two (2) weeks prior to the 6 month deadline, and will automatically disable
access to the network and servers at the 6 month deadline if the employee fails to change
the password. The employee then must report to the information security manager to
reactivate the account.
Access to Liberty Beverage is only authorized on Liberty Beverage systems by any
Liberty Beverage employee only using his or her assigned credentials only while
“clocked in” for work during an assigned shift. Access to Liberty Beverage in any other
manner or at any other time by any other individual is unauthorized.
The information contained within this policy supersedes any previous information,
structured or informal, on this subject. Training on this policy will be held for every new
employee during orientation and for every other employee yearly.
3. Highly Recommended Practices
Employees may step away from the system they are using and for a lack of having to
log in upon returning decide to remain logged in while away from the system. This is an
unauthorized practice and a violation of this policy. All employees will log out of the
system at any time he or she leaves the station. This will ensure that no unauthorized
access to the information is allowed while the employee is away from the system.
It is common practice while using personal servers, accounts, or profiles to share
password information with another trusted individual. This is an unauthorized practice
and a violation of this policy. All employees will maintain a level of confidentiality as it
relates to passwords for all Liberty Beverage accounts, servers, and profiles.
Use of passwords that fail to meet the minimum security strength requirements leave
room for attackers to breech the Liberty Beverage network and servers. Employees will
ensure that their password meets the required minimum security level as outlined in the
Password Construction Guidelines section 2.5 of this policy.
Employees will refrain from writing down and carelessly securing the passwords for all
Liberty Beverage accounts. An attacker can locate this password and gain unauthorized
access to the Liberty Beverage accounts, profiles, or network
Employees are discouraged from choosing passwords for their Liberty Beverage
accounts, profiles, or the network that are already used for personal accounts or profiles.
Doing so would cause any exploitation of an employee’s personal account or profile to
be a risk for potential exploitation of Liberty Beverage accounts and network.
Liberty Beverage will grant certain employees system level privileges due to their status,
position, or title. These employees are not to use the same password for multiple levels
of access to the Liberty Beverage network.
Employees must not use the “remember password” in an effort to refrain from
maintaining their passwords. While this does allow for convenience, it also generates a
potential risk as any other individual can now utilize the system via the employee’s
saved password and potentially access the server, network, or cause damage using that
employee’s profile.
Password cracking or guessing may be performed on a periodic or random basis by the
Information Security Team or its delegates. If a password is guessed or cracked during
one of these scans, the employee will be required to change it to be in compliance
with the Password Construction Guidelines outlined in section 2.5.
4. Policy Compliance
Information Security teams will verify compliance to this policy through various
methods, including but not limited to, periodic walk-thrus, video monitoring,
internal and external audits, and provide feedback to the management team
Exception to this policy will be granted on a case by case basis. Any exception to the
policy must be approved by the Information Security Team in advance.
Any employee found to have violated this policy may be subject to disciplinary
action, up to and including termination of employment