-
What password policy should be adopted?
A database contains the personal data of hundreds or thousands of people, and teachers are particularly vulnerable to password theft (whether they log in directly or via a DW) because they frequently enter their passwords in the presence of students or others.
Our role is to propose solutions to protect data, the responsibility of each is to adapt its security according to its context of use.
Regardless of the context, the Principal must ensure the following.
Our role is to propose solutions to protect data, the responsibility of each is to adapt its security according to its context of use.
Regardless of the context, the Principal must ensure the following.
Password composition rule
The default password composition rule is evolving with the recommendations of the CNIL. Currently, it imposes a minimum size of 8 characters and 3 complexity criteria:
- At least one numeric character
- At least two letters
- Mix of lower and upper case letters
Caution, if you recover the passwords from year to year, you must force their change to apply this rule.
Password renewal
It is necessary to impose a regular renewal of the password. A simple way to do this is not to recover passwords from year to year: at the beginning of each school year, you give a new temporary password to each user who personalizes it at the time of his first connection.
Another way is to encourage or force password changes every X days. Depending on the option chosen, users are informed that it is advisable or necessary to change their passwords.
Another way is to encourage or force password changes every X days. Depending on the option chosen, users are informed that it is advisable or necessary to change their passwords.
Double-authentication
To comply with the recommendations of the CNIL, we propose by default to teachers and staff to enter a PIN code and/or send notifications when connecting from any new device.
It is best to maintain these safety measures.
It is best to maintain these safety measures.
User awareness
It is recommended that users be reminded of the essential rules to follow: keep your password secret, do not write it down or type it out of sight, etc.
To go a step further
VHere are some references regarding password security:
- Deliberation No. 2017-012 of January 19, 2017 - Public service for the diffusion of law
- CNIL tips for a good password - CNIL
- Minimum security recommendations - CNIL
- Good IT practices - ANSSI-list 2
Was this content useful to you?
Can't find an answer to your question ?
Contact our support