Showing posts with label iso27001 password controls. Show all posts
Showing posts with label iso27001 password controls. Show all posts

Friday, February 3, 2012

ISO27001 and Password Controls

I take a look at very a number of firms each and every year and those searching for certification to ISO27001, the specifics security management common, are rising in numbers.


The very first step in any 27001 assignment involves a gap audit to see how near (or far) the organization is from meeting this common. Typically it transpires that some substantial function is needed to meet this exacting normal.


To put the common into perspective If ISO9001, the top quality management regular, equated to a molehill then 27001 would equate to Everest. I hope I haven't put you off!!


1 of the sections within 27001 offers with access manage and the part I want to cover is the control and use of passwords. Here are some guidelines for passwords:




  • Passwords ought to be complicated, i.e need to be six characters or far more, ought to contain at least one particular number, a single uppercase letter and if feasible a non alpha or numeric character. I often put £ in my passwords since only UK keyboards have this.
  • The password should certainly not be in a dictionary either forwards or backwards.
  • Never ever use Pa33w0rd (Password) or lEt m3 1n (letmein) or a pet or partners name.
  • Never disclose your password to anybody
  • Alter your password often
  • By no means write it down unless it is heavily disguised.


I see breaches of these rules on a normal basis including:




  • Post it notes with the password stuck to monitors or below keyboards.
  • Passwords with 3 characters
  • Passwords that are honestly obvious like January-week 1, which increments to January-week two and so on.


Most systems can be hacked in a reasonably short time so I recommend that a computer system really should lock if additional than a set number of incorrect passwords is entered. Make it tougher and time consuming for the hacker.


Let us make 2011 a far more secure year for our computer system systems. Don't forget the data on your technique is precious and can lead to a outstanding deal of distress, if not monetary loss if it is stolen by other individuals.

Tuesday, September 20, 2011

ISO27001 and Password Controls

I visit quite a number of companies each year and all those seeking certification ISO 27001, information security management standards, are growing in numbers.


The first step in any task involves 27,001 gap audit to see how close (or far) the company from meeting this standard. Usually, it is evident that some significant work is necessary to meet this demanding standard.


that the standards in perspective, if the ISO9001, quality management standards, equated with the molehill, then amounted to 27 001 Everest. I hope I have not put off !!


One of the parts within 27 001 deals with access control, and I want to cover part of the control and use passwords. Here are some rules for passwords:




    Passwords should be complex and must be six characters or more, must contain at least one number, one uppercase letter, and if you can not alpha or numeric character. I often put the pounds in my password, because only the UK this keyboard.
    password should not be in the dictionary, or forward or backward.
    Never use Pa33w0rd (passwords) or a m3 1n ​​(letmein) or a pet or partner's name.
    never give your password to anyone
    Change passwords regularly
    never write it down, unless it is heavily disguised.


I see violations of these rules on a regular basis, including:




    Post it notes with a password stuck on monitors or under keyboards.
    passwords with three characters
    passwords that are really obvious as the week of January 1, which increments until January, two weeks and so on.


Most systems can be hacked within a relatively short time, so I recommend that the computer should be locked if there is more than a certain number of incorrect password is entered. Make it more difficult and time consuming to hack.


Let's make 2011 a safer year for our computer systems. Remember the data on your system is valuable and can cause much distress, if not financial loss if it is stolen by others.

Monday, September 19, 2011

ISO27001 and Password Controls

I visit quite a number of companies each year and all those seeking certification ISO 27001, information security management standards, are growing in numbers.


The first step in any task involves 27,001 gap audit to see how close (or far) the company from meeting this standard. Usually, it is evident that some significant work is necessary to meet this demanding standard.


that the standards in perspective, if the ISO9001, quality management standards, equated with the molehill, then amounted to 27 001 Everest. I hope I have not put off !!


One of the parts within 27 001 deals with access control, and I want to cover part of the control and use passwords. Here are some rules for passwords:




    Passwords should be complex and must be six characters or more, must contain at least one number, one uppercase letter, and if you can not alpha or numeric character. I often put the pounds in my password, because only the UK this keyboard.
    password should not be in the dictionary, or forward or backward.
    Never use Pa33w0rd (passwords) or a m3 1n ​​(letmein) or a pet or partner's name.
    never give your password to anyone
    Change passwords regularly
    never write it down, unless it is heavily disguised.


I see violations of these rules on a regular basis, including:




    Post it notes with a password stuck on monitors or under keyboards.
    with a three-character passwords
    passwords that are really obvious as the week of January 1, which increments until January, two weeks and so on.


Most systems can be hacked within a relatively short time, so I recommend that the computer should be locked if there is more than a certain number of incorrect password is entered. Make it more difficult and time consuming to hack.


Let's make 2011 a safer year for our computer systems. Remember the data on your system is valuable and can cause much distress, if not financial loss if it is stolen by others.