Skip redundant pieces

University of Kansas Medical Center Operational Protocol: Password Security


Principle

New passwords will be provided, and existing passwords will be released, only when the identity of the requester can be clearly established.

Background

The University of Kansas Medical Center provides access to network, electronic mail and voice mail resources to its students, faculty, and staff, in support of the University's mission of teaching, research, and public service. Passwords are assigned for access to each of these resources to authenticate a user's identity, to protect network users, and to provide security.

Password protection is one of the most important principles of network, e-mail and voice mail security. The purpose of this policy is to outline the procedures used by authorized staff to change or reveal an existing password to users who have compromised or forgotten their authorized password to the University’s network, e-mail or voice mail resources. The resources covered by this policy include, but are not limited to, the University’s network (via campus or remote access), e-mail and voice mail systems.

Although the University strives to manage a secure computing and networking environment, the University cannot guarantee the confidentiality or security of network, e-mail or voice mail passwords from unauthorized disclosure.

Definitions

PASSWORD- Authorized individual password assigned by the University of Kansas Medical Center’s Information Resources Department for access to its network, e-mail and voice mail resources.

UNIVERSITY- The term 'the University' means the University of Kansas Medical Center.

USER- Anyone who holds a valid account on the University’s network, e-mail and/or voice mail systems.

Exemptions

Everyone who holds, or wishes to acquire, a valid account on the University’s network, e-mail and/or voice mail systems is covered by this policy. This policy covers users on the Kansas City and Wichita campuses as well as users who access these systems from an off-campus location. There are no exemptions.

Procedures

I. Password request procedures.

Procedures for processing password requests strive to balance security requirements and user convenience. These procedures will be followed by staff of Customer Support or of the Instructional Technology Center for all password requests (including new, changed or forgotten passwords) for access to the University’s network, e-mail or voice mail resources.

1. Under no circumstances will existing passwords be revealed by telephone.

2. Under no circumstances will new passwords be provided by telephone.

3. Customer Support and Instructional Technology Center staff will be pleased to handle requests made in one of the following ways:

  • Requests may be made in person at Customer Support [3021 Taylor] 7 a.m. – 9 p.m. Monday-Friday or the Instructional Technology Center during staffed hours. Photo identification is required.
  • Requests may be faxed to Customer Support at 913/588-2579 7 a.m. – 9 p.m. Monday-Friday. The fax must include photo identification and signature. Nights, weekends, and holidays, requests may be faxed to Computer Operations at 913/588-4924.
  • Requests may be submitted via web form. New account requests must be verified by the Registrar's Office or by the employee's department.

4. Confirmation will be sent to user by e-mail or alphanumeric page when a password change is completed.

5. A network manager must approve any password change requested by a user's supervisor. Confirmation will be sent to user when a password change is completed at the request of a supervisor.

6. Department network specialists may complete password requests for their own users. However, any user who is unable to prove identity to the department network specialist's satisfaction must resubmit the change request following Customer Support/ITC procedures.

II. Password Protection Responsibilities

System administrators and users assume the following responsibilities:

  • System administrator must protect confidentiality of user’s password.
  • User must create and manage passwords according to the Password Standards outlined below.
  • User is responsible for all actions and functions performed by his/her account.
  • Suspected password compromise must be reported to Information Security (8-3333) immediately.

Password Standards

KUMC has adopted "complex passwords" to make it harder for someone to "crack" one of our passwords.   Passwords for access to the KUMC network and computer systems must meet the following requirements:

  • Consist of 8 to 14 characters.
  • Utilize a mix of upper-case and lower-case letters (at least one of each case).
  • Include at least one number.
  • Include at least one punctuation character (e.g., !# or *.
  • Must be changed on an annual basis.

To minimize password guessability:

  • Use two or three short words that are unrelated.
  • Deliberately misspell words.
  • Take the first letter from each word of a phrase.
  • Do not use any part of the account identifier (your login ID, name, etc.).
  • Do not use a proper name or any word in the dictionary without altering it in some way.

Keep your password safe:

  • Do not tell your password to anyone.
  • Do not let anyone observe you entering your password.
  • Do not display your password in your work area or any other highly visible place.
  • Change your password periodically (while password change is required on an annual basis for campus systems, every 3 months is recommended).
  • Do not reuse old passwords.

Additional Security Practices

  • Ensure your workstation is reasonably secure in your absence from your office.  Either log off when you are away or press the CTRL, ALT and DEL keys and choose "Lock Computer" to lock your screensaver.

Contact Information

For information on this policy, please contact:

Jim Bingham
Associate Vice Chancellor for Information Resources
Chief Information Officer
University of Kansas Medical Center
1014 Taylor, 3901 Rainbow Blvd
Kansas City, Kansas 66160
(913) 588-7300

Sherry Callahan
Director of Information Security
Department of Information Resources
University of Kansas Medical Center
1020 Taylor, 3901 Rainbow Blvd
Kansas City, Kansas 66160
(913) 588-0966

top of page