TMCnews


TMCnews Featured Article


July 05, 2011

Useful Resources for Enterprise Password Management Presented

By David Sims, TMCnet Contributing Editor


Forget all the horror stories you hear about millions of passwords being swiped with ease implying that they’re not important. They are. Don’t treat your passwords cavalierly, using your first name or “123456” as your password on the theory that “Hey, if a hacker wants to steal it he will anyway.” Enterprise password management begs to differ.

Passwords are, in fact, your first and best defense against identity theft.

So it’s a bit puzzling why passwords ”remain one the of the most fragile” means used by businesses to safeguard their user accounts, networks and data, as industry observer Ken Hardin writes, “despite constant warnings that users are simply awful at managing passwords and that even the best passwords cannot replace other measures, such as encryption, to protect your most valuable assets.”

 Hardin points to some useful resources for enterprise password management, in the “Enterprise Password Management Guide” put together by The National Institute of Standards and Technology, of interest to enterprise password management pros and more sophisticated users. It deals with what Hardin says are “hardwired issues relating to what might appear to be something as simple as passwords,” dispensing such advice as “be sure to encrypt files on hosts that contain passwords to make life harder on hackers,” and “lock out users who make excessive, repeated failed attempts to log on.”

 “Protecting Your Passwords” is a PowerPoint presentation from The Computer Guy, which Hardin says is designed for IT to try to relay the essential points of safe, careful enterprise password management to the weak links in any security chain in many situations – the end users.

The presentation contains such advice as “never even say your password aloud” and “don’t use personal info, like telephone or Social Security numbers, in your password.”

It was only last month that TMCnet spoke about some of the most common enterprise management password mistakes made by administrators, which include allowing weak passwords, connecting to unknown and (sometimes unsecured) Wi-Fi HotSpots and not performing vulnerability scans or audits on a regular basis.


David Sims is a contributing editor for TMCnet. To read more of David’s articles, please visit his columnist page. He also blogs for TMCnet here.

Edited by Jamie Epstein