Privacy and Security Notice

Password Regulations

Password Rules

Note: For procedures on changing passwords, see http://cc.jlab.org/docs/services/cue/password.html.

In accordance with DOE Notice 205.3 and guidance in 205.3-1, all passwords in use on any system at Jefferson Lab must be in accordance with the following rules and guidelines.

Password Selection

  1. Password contains at least eight non-blank characters, provided such passwords are allowed by the operating system or application. Your password can be longer than eight characters, but not less than.
  2. Password contains a combination of letters (a mixture of upper and lower case), numbers, at least one special character, all within the first eight positions, provided such passwords are allowed by the operating system or application.
  3. Password contains a non-numeric in the first and last position.
  4. Password does not contain any part of your username or common name.
  5. Password does not include the user's own or, to the best of his/her knowledge, close friends - or relatives - names, employee serial number, Social Security number, birth date, phone number, or any information about him/her that the user believes could be readily learned or guessed.
  6. Password does not, to the best of the user's knowledge, include common words that would be in an English dictionary, or from another language with which the user has familiarity.
  7. Password does not, to the best of the user's knowledge, employ commonly used proper names, including the name of any fictional character or place.
  8. Password does not contain any simple pattern of letters or numbers, such as "qwertyxx' or "xyz123xx".
IMPORTANT -- All password requirements MUST be met in the first 8 characters of your password (at least one uppercase, one lowercase, one numeric, and one special character).

Password Protection

Individuals must not:

  1. share passwords; the only exception is "in emergency circumstances or when there is an overriding operational necessity".
  2. leave clear-text passwords in a location accessible to others or secured in a location whose protection is less than that required for protecting the information that can be accessed using the password;
  3. enable applications to save passwords for subsequent re-use.

Password Changing

Passwords must be changed:

  1. at least every 6 months;
  2. immediately after sharing;
  3. as soon as possible, but within 1 business day after a password has been compromised, or after one suspects that a password has been compromised;
  4. on direction from management.

This document is maintained by {helpdesk@jlab.org}

Copyright Jefferson Lab 2007