Essentials of Proper Password Protection

Re-published with permission from White-Collar Crime Fighter, www.wccfighter.com.

It may sound surprising, but too many companies still don't live by the seemingly obvious rule that computer security is heavily dependent on a tight password protection system...and that the password system in turn depends on the passwords being kept secret at all times.

Problem: A password is vulnerable to compromise whenever it is used, stored or even known. In a password-based authentication function implemented on a system, passwords are vulnerable to compromise due to six essential aspects of the password system...

  1. A password must be initially assigned to a user when he or she is admitted to the system. Vulnerability: Potentially malicious tendencies on the part of the issuer--usually the system administrator.

  2. A user's password should be changed periodically. Vulnerability: The longer the user uses the password, the more time an attacker has to crack it.

  3. The system must maintain a "password database." Vulnerability: If the database is compromised all passwords may be compromised.

  4. Users must remember their passwords. Too many passwords and users begin to write them down or use common names such as family, friends or birthdates.

  5. Users must enter their passwords into the system at authentication time. Vulnerability: Shoulder surfers can pick up the password when the user enters it.

  6. Employees may not disclose their passwords to anyone. Vulnerability: Sometimes attackers will pose or spoof themselves as managers, administrators or other high-level people within the organization. Users must never disclose their passwords, no matter who has asked for them.

To mitigate some of these risks, formulate and enforce policies based on your organization's specific needs.

Examples: You can specify minimum password length...no blank passwords...and maximum and minimum password age. You can prevent users from reusing passwords and/or require users to include specific characters in their passwords.

Other options include use of expensive but effective technologies such as biometric scanners and smart card readers. These are generally used in conjunction with password systems in high-security environments.

White-Collar Crime Fighter source: Edmund J. Pankau, a nationally renowned author, CPP, CLI, DABFE (Diplomate, American Board Forensic Examiners), President of Pankau Consulting, a Houston-based international security consulting agency.

You may like these other stories...

Cybersecurity is no longer the domain of an organization's IT staff. It's moved to the boardroom, and in a big way. Accountants and financial managers may have been thinking it's just the province of the tech...
You probably don't want to think about how many times you access the File menu in Excel 2010 or 2013. Personally I think Excel 2010 has the best possible File menu arrangement, other than having Print Preview grafted...
Following other recent high-profile hacking events, investigators discovered yesterday that hackers broke into the draft work paper files of several famous CPA firms. Revealing images of the scantily clad documents have been...

Already a member? log in here.

Upcoming CPE Webinars

Sep 24
In this jam-packed presentation Excel expert David Ringstrom, CPA will give you a crash-course in creating spreadsheet-based dashboards. A dashboard condenses large amounts of data into a compact space, yet enables the end user to easily drill down into details when warranted.
Sep 30
This webcast will include discussions of important issues in SSARS No. 19 and the current status of proposed changes by the Accounting and Review Services Committee in these statements.
Oct 21
Kristen Rampe will share how to speak and write more effectively by understanding your own and your audience's communication style.
Oct 23
Amber Setter will show the value of leadership assessments as tools for individual and organizational leadership development initiatives.