Most users of information systems are well aware of how important proper management of authentication credentials is for security. Nevertheless, often without giving it much thought, this security measure is downplayed, with the belief that only the IT department is responsible for the security of their infrastructure.
However, this is not entirely the case. You can discuss password policies in information systems with Cezary Lutyński – our data protection advisor. Contact him to schedule a free consultation.
Legal Requirements
Regarding the complexity, length, and frequency of changing access passwords to information systems where personal data processing occurs, until May 25, 2018, we were subject to the provisions of the MSWiA Regulation. These provisions specified that in situations where at least one device in the local network infrastructure is connected to a public network, access passwords to such systems should consist of at least 8 characters and include a mix of uppercase and lowercase letters, numbers, or special characters. Additionally, they were to be changed at least every 30 days, which was certainly the most disliked parameter.
Considering the fact that, according to best practices, access credentials for each of the systems used should be different, this led to user rebellion. This is not surprising, as even with just a few corporate systems, combined with a few personal services, ultimately each of us has to remember many passwords, including long, complex, and frequently changing ones. Thus, enforcing such a password policy often did not build security but rather had the opposite effect, leading to the recording of login data at workstations or often in other easily accessible places. And do you know the popular small yellow sticky notes stuck under the keyboard or on the monitor screen?
More
on violations can be found in the article: "Dangerous Desks: How Employees Endanger Companies".
The European Regulation on the Protection of Personal Data, which came into effect on May 25, 2018, provides a completely new approach regarding the use of passwords. The requirement for appropriate password complexity, minimum length, and, most importantly, frequency of change has been abolished. Many people reading this article may have breathed a sigh of relief... Unfortunately, until organizations decide to implement another form of authentication, we will still have to change passwords, albeit less frequently than before. After all, we cannot compromise security for user convenience. According to point 84 of the GDPR preamble, the data controller will need to select appropriate technical and organizational measures to secure the processed personal data based on a conducted risk analysis. A properly conducted process aims to identify threats to the organization's IT infrastructure, prioritize them, estimate potential losses associated with security breaches, and propose reasonable solutions to mitigate the risk of incidents.
In other words, not only an appropriate password policy in IT systems but also all other technical and organizational safeguards should result from such a process. Its goal is to identify areas or resources that are not secured or where the applied safeguards are insufficient. This refers to resources that pose the highest likelihood of the identified threats materializing within the organization, and thus their use carries a high risk for personal data. Such a resource exceeding the so-called threshold of acceptability set by the organization could indeed be an IT system. This means that based on the identified threat and the results of the estimated risk for such a resource, the organization can decide to mitigate or tighten the applied password policy or maintain it at the current level, while focusing risk-minimizing actions on another element of the system.
The provided text does not contain any translatable content as it consists solely of XML and Word document formatting code. Please provide the actual Polish text that requires translation.SemiHidden="true" UnhideWhenUsed="true" Name="index 4"/>More
about risk analysis can be found in our article:
"Risk Assessment in accordance with GDPR - Introduction".
Password Policy under GDPR in Practice
Under the applicability of the GDPR, most organizations choose to ease their password policy in favor of extending the frequency of password changes. The most commonly selected period is 3 months, while the remaining requirements remain unchanged. However, what happens when employees in our organization have access to a large number of systems, and remembering all passwords that change even every 90 days is impossible for them? A good way to address this issue and make life easier for users is to provide each of them with password manager software. This way, access to the encrypted database of their credentials will be protected by one strong key, and the employee will only need to remember the password for the operating system, possibly for disk decryption, and the password manager. A popular free program of this type is KeePass. It is a safe for passwords that not only securely stores our login data but also generates strong passwords, which it will then automatically input into the login panels of the systems we use.
Should We Never Write Down Passwords?
A fundamental principle of handling access passwords is, among other things, the prohibition of writing them down in easily accessible places. However, there are exceptions to every rule, and this is also the case here. The best example is administrative passwords used by the IT department. Due to the continuity of IT systems, the main administrator's password should be written down and properly secured, for example, by depositing it in a safe, in a specially sealed envelope with access limited to a strictly defined number of individuals. The envelope should prevent the password from being seen, and any attempt to open it should leave visible traces. This action aims to prevent a situation where the administrator decides to leave the ranks of our organization's employees or experiences some misfortune, and we will not be able to perform any administrative actions without having such data. Although these are not everyday occurrences, it is worth remembering, as such a situation can lead to paralysis of the organization.
Of course, in the case of a larger number of administrators or individuals with privileged access, it is also necessary to ensure that each of them has an individual identifier and password. This will prevent the loss of accountability, which allows us to verify the actions performed by a specific person in the system logs. Furthermore, the prohibition on sharing identifiers should apply not only to administrators but also to all users of IT systems.
Other tips for building a password policy
Establishing a password policy, especially when managing a larger number of computers, is certainly facilitated by the Active Directory catalog service, which allows us to standardize settings across the entire local network easily. In addition to the requirements described above from the previous legal state and currently used practices, let us not forget about configuring other elements of the password policy, such as:
- configuring the retention of recently used passwords. This will prevent a situation where a user, during a system-mandated password change, sets the same key they previously used,
- temporarily or permanently blocking accounts after multiple attempts to enter incorrect login data. Ideally, the system should automatically notify the administrator of such a block. This solution minimizes the risk of credential breaches through brute force attacks and allows for greater control over other unauthorized intrusion attempts,
- configuring a minimum password lifetime. This is a solution rarely implemented by IT system administrators, but it is certainly worth implementing. To bypass the security regarding the retention of recently used passwords, for example, a count of 10, one would need to demonstrate considerable cunning; however, more advanced and resistant users may come up with the idea of changing their password so many times that they can eventually return to the key they previously used. The minimum password lifetime rule will certainly effectively hinder them,
- enforcing the change of temporary passwords. A common mistake made by employees is failing to change the password provided by the IT department for the initial login. If the system does not enforce such a change or the user does not perform this action manually, we face a lack of accountability for actions during the period in which it was used. Often, employees are unaware that since they are using login data provided by another person (regardless of whether it is the IT department), it means that someone else also has access to this data. It is important to remember that system logs will attribute any actions performed on the user's access account to its owner, not to the person who actually acted in the system.
Are organizational procedures sufficient?
Considering the effectiveness of organizational procedures and the importance of strong passwords, it is best if the system imposes the appropriate requirements. However, the organization cannot eliminate all unreasonable user behaviors regarding login credentials through rules enforced by the system. Therefore, in order to exercise due diligence as a data controller and to clearly impose responsibility on employees in the work regulations, IT system management instructions, or other documents that users formally acknowledge, appropriate provisions regarding the handling of confidential authentication credentials should be included. Periodic training to raise employee awareness will also be necessary.
More
on employee education can be found in the article:
"Personal data protection in the workplace – how to educate employees?".
Below are some basic principles that every user of an IT system should remember. If you are reading this article and are responsible for security in your organization, please share it with employees as part of a security bulletin:
- under no circumstances share your passwords with anyone! Not even with the IT technician. If access to your documents stored on your computer's hard drive is needed, the IT department will obtain it through the administrative account. A password is confidential information that you should not share with anyone,
- if you suspect that your authentication data has been disclosed, change your password immediately! This way, you will prevent or limit the effects of a data leak. Next, promptly inform the IT systems administrator or another authorized person about the situation,
- immediately after your first login, change the temporary access password! If you do not do this, you may be held responsible for actions taken by someone else on your account,
- do not use passwords that contain your username, and when changing them periodically, do not use variations of previous ones! This will make it more difficult for unauthorized individuals to breach your login credentials,
- use different passwords for each system! Breaching credentials for one system will not compromise data in other systems,
- do not write down passwords in easily accessible places, especially right next to your workstation. If you cannot remember them all, ask the IT department to install software for storing login credentials in an encrypted format.
Although password-based authentication methods are very popular and relatively simple to use, many users as well as data controllers make glaring mistakes in this regard. As long as the authentication systems known from movies, based on retina scanning, vascular pattern analysis, or voice tone characteristics, are not financially accessible to everyone and are not fully effective, we should approach our authentication credentials, which are passwords, with great care. This will minimize the risk of data leakage or breaches, and consequently the risks of loss of confidentiality, integrity, or availability of our data.




