Approved by President/Provost
4/8/2020
Review again
4/8/2025
Policy Contact
ITS Security and Client Computing
(607) 436-3203
Category
Information Technology Policies
Policy Statement
This policy outlines password management requirements for SUNY Oneonta user accounts.
Rationale
Passwords are a common means of authenticating a user’s identity when accessing information systems. Password standards need to be implemented to ensure all authorized individuals accessing SUNY Oneonta resources follow proven password management practices. These password rules must be mandated by automated system controls whenever possible.
Applicability of the Policy
This policy applies to all SUNY Oneonta faculty, staff, students, and all other users of relevant information systems.
Policy Elaboration
To ensure proper password management, the following password standards will be implemented where technically feasible: |
||
|
||
|
|
|
Definitions
Suspicious login attempt behavior - Login attempt patterns identified by ITS Security and Client Computing as indicators of attempted compromise. For example, excessive failed login attempts in a given time frame that would suggest a brute-force attempt to guess an account password.
Contacts
Questions related to the daily operational interpretation of this policy should be directed to:
ITS Security and Client Computing
(607) 436-3203
Effective Dates
Approved by the President/Provost on 4/8/2020