CJIS/NCIC PASSWORDS AND PROCEDURES
1200.1 OVERVIEW
Passwords are an important aspect of computer security. They are the front line of protection for user accounts. A poorly chosen password may result in a compromise of the Lincoln Police Department's entire network. As such, all Lincoln Police Department employees (including contractors and vendors with access to Lincoln Police Department systems) are responsible for taking the appropriate steps, as outlined below, to select and secure their password.
________________________________________________________________________________________________________________________
1200.2 PURPOSE
The purpose of this policy is to establish a standard for the creation of strong passwords, the protection of those passwords, and the frequency of change.
________________________________________________________________________________________________________________________
1200.3 SCOPE
The scope of this policy includes all personnel who have or are responsible for an account (or any form of access that supports or requires a password) on any system that resides at any Lincoln Police Department facility, has access to the Lincoln Police Department network and/or NCIC network, or stores any nonpublic Lincoln Police Department information.
________________________________________________________________________________________________________________________
1200.4.1 GENERAL
All systems-level passwords (e.g., root, enable, network administrator, application administration accounts, etc.) must be changed at least every 90 days.
All user-level passwords (e.g., email, web, desktop computer, etc.) must be changed at least every 90 days.
Where simple network management protocol (SMTP) is used, the community strings must be defined as something other than the standard defaults of "public," "private, "and "system" and must be different from passwords used to log in interactively. A keyed hash must be used where available (e.g., SNMPv2).
________________________________________________________________________________________________________________________
1200.4.2 GUIDELINES
Passwords are used for various purposes at Lincoln Police Department. Some of the more common uses include: user-level accounts, web accounts, email accounts, screen saver protection, voicemail password, and local router logins. Since very few systems have support for one-time tokens (i.e., Dynamic passwords which are used once), everyone should be aware of how to select strong passwords.
Poor, weak passwords have the following characteristics:
Name of family, pets, friends, co-workers, fantasy characters, etc.
Computer terms and names, commands, sites companies, hardware, software.
Word or number patterns like aaabbb, 111222, zyxwvts, 4654321, etc.
Strong passwords have the following characteristics:
Have digits and punctuation characters as well as letters, e.g., 0-9,!@#$%^&*()_+{}[]:";<>?,.?
Are not a word within any language, slang, dialect, jargon, etc.
Passwords based on a song title, affirmation, or other phrase. For example, the phrase might be: "This May Be One Way To Remember" and the password could be: "TmB1w2R!" or "Tmb1W>r~" or some other variation. NOTE: Do not use either of these examples as passwords
________________________________________________________________________________________________________________________
1200.4.3 PASSWORD DELETION
All passwords that are no longer needed must be deleted or disabled immediately. This includes, but is not limited to, the following:
When a user retires, quits, is reassigned, released, dismissed, etc.
CJIS/NCIC PASSWORDS AND PROCEDURES
Contractor accounts, when no longer needed to perform their duties. When a password is no longer needed, the following procedures should be followed:
________________________________________________________________________________________________________________________
1200.4.4 PASSWORD PROTECTION STANDARDS
Do not use your user id as your password. Do not use the same password for Lincoln Police Department accounts as for NCIC accounts. For example, select one password for your Windows account login and a different one for your NCIC account login. Do not share Lincoln Police Department passwords with anyone, including administrative assistants or secretaries. All passwords are to be treated as sensitive, Confidential Lincoln Police Department information.
Here is a list of "do not's"
If someone demands a password, refer them to this document or have them call <list name of Information Security Officer (ISO) or Agency POC. If an account or password is suspected to have been compromised, report the incident to Lincoln Police Department
CJIS/NCIC PASSWORDS AND PROCEDURES
ISO or POC and change all passwords.
Password cracking or guessing may be performed on a periodic or random basis by the FBI or <Agency Security Department or POC>. If a password is guessed or cracked during one of these scans, the user will be required to change it.
________________________________________________________________________________________________________________________
1200.5 APPLICATION DEVELOPMENT STANDARDS
Application developers must ensure their programs contain the following security precautions:
Should support Terminal Access Controller Access Control System+ (TACACS+), Remote Authentication Dial-In User Service (RADIUS), and/or X.509 with Lightweight Directory Access Protocol (LDAP) security retrieval, wherever possible.
________________________________________________________________________________________________________________________
1200.6 REMOTE ACCESS USERS
Access to the Lincoln Police Department networks via remote access is to be controlled by using either a Virtual Private Network (in which a password and user id are required) or a form of advanced authentication (i.e., Biometrics, Tokens, Public Key Infrastructure (PKI), Certificates, etc.).
________________________________________________________________________________________________________________________
1200.7 ENFORCEMENT
Any employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.