Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Southern Class & Sass
 
Dixie's Avatar
 
Join Date: Feb 2005
Location: Bradenton, FL
Posts: 4,018
Garage
Quote:
Originally Posted by masraum View Post
For instance, you could remember
Sec question 1 answer or 1st grade teacher: purple people eater
Sec question 2 answer or mother's maiden name: blueberry
Sec question 3 answer or first pet's name: clockwork orange

Or the question is the answer.
1) First Grade
2) Mother's Maiden
3) First Pet

__________________
Dixie
Bradenton, FL
2013 Camaro ZL1
Old 07-17-2024, 11:30 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #21 (permalink)
Driver, not Mechanic
 
Join Date: May 2013
Location: SF Bay Area
Posts: 3,002
Quote:
Originally Posted by flipper35 View Post
I guess what I meant was an HR policy.
We are already 16 char complex, 90 days, no less than the last 10, can't reuse within 30 days to eliminate password recycling, we use Duo and MSAuthenticator for MFA.

What we want is a written policy that they will use MFA and use a password manager to create passwords for each site they go to. Specifically a policy in HR where there are consequences for not following the policy - for example password files or handwritten passwords to keep track.

At the moment, we can only tell people to not do bad things.

My previous place where I was director of IT it was a no questions asked termination of you wrote your password down at your desk. That was in healthcare.
I've not seen this on an HR Policy/Employee Handbook. They simply reference a Security Policy. E.g. "All ACME employees are expected to follow the policies outlined in the Acme Data Privacy and Security Policy. Violations of this policy can result in disciplinary action and/or termination of employment." And then in that linked security policy document, you outline the ones you mentioned.
Old 07-17-2024, 03:03 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #22 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,975
Sorry passwords for what? What are you protecting, internal system, SaaS apps, ?

MFA and password managers are a must these days, I have hundreds of passwords for things and I don’t know a single one If an employee gets let go or quits, their account is disabled and they have access to nothing.
Password less is the new buzz, but start with something like Duo and Passportal, you could use the excuse the password manager forces us to use complex passwords

__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 07-17-2024, 09:56 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #23 (permalink)
Reply


 


All times are GMT -8. The time now is 12:59 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.