- Practical Linux Security Cookbook
- Tajinder Kalsi
- 314字
- 2021-07-16 11:05:28
Configuring password protection
In any system, the password plays a very important role in terms of security. A poor password may lead to an organization's resources being compromised. The password protection policy should be adhered to by everyone in the organization, from users to the administrator level.
How to do it…
Follow the given rules when selecting or securing your password.
For the creation policy, follow these rules:
- A user should not use the same password for all the accounts in an organization
- All access-related passwords should not be the same
- Any system-level account should have a password that's different from any other account held by the same user
For the protection policy, follow these rules:
- A password is something that needs to be treated as sensitive and confidential information. Hence, it should not be shared with anyone.
- Passwords should not be shared through any electronic communication, such as e-mails.
- Never reveal a password on your phone or questionnaire.
- Do not use password hints that could provide clues to an attacker.
- Never share company passwords with anyone, including administrative staff, managers, colleagues, and even family members.
- Don't store passwords in written form anywhere in your office. If you store passwords on a mobile device, always use encryption.
- Don't use the Remember Password feature of applications.
- In there's any doubt of a password being compromised, report the incident and change the password as soon as possible.
For the change policy, follow these rules:
- All users and administrators must change their password on a regular basis or at least on a quarterly basis
- The security audit team of an organization must conduct random checks to check whether the passwords of any user can be guessed or cracked
How it works…
With the help of the preceding points, ensure that a password, when created or changed, is not easy enough to be guessed or cracked.
推薦閱讀
- Django+Vue.js商城項(xiàng)目實(shí)戰(zhàn)
- Google Apps Script for Beginners
- Rake Task Management Essentials
- TestNG Beginner's Guide
- The Complete Coding Interview Guide in Java
- Android開(kāi)發(fā):從0到1 (清華開(kāi)發(fā)者書(shū)庫(kù))
- OpenStack Orchestration
- 深入淺出React和Redux
- Mobile Device Exploitation Cookbook
- 運(yùn)維前線:一線運(yùn)維專(zhuān)家的運(yùn)維方法、技巧與實(shí)踐
- ActionScript 3.0從入門(mén)到精通(視頻實(shí)戰(zhàn)版)
- C#面向?qū)ο蟪绦蛟O(shè)計(jì)(第2版)
- Ext JS 4 Plugin and Extension Development
- PHP項(xiàng)目開(kāi)發(fā)全程實(shí)錄(第4版)
- 計(jì)算機(jī)應(yīng)用基礎(chǔ)案例教程(第二版)