I've been tasked to come up with password proceedures. The thought being that we want more secure procedures than what we are currently using. Things such as:
(1) When to change them.
(2) Formats - Random passwords, upper/lowercase, not alpha characters, etc.
(3) access control - who gets access to these passwords, when,
(4) when to change them.
What I'm looking for comments on is what are the rest of you doing for this. Especially you dealers.
Some obvious issues is that when using unique passwords for every customer/site/system, how do you ensure that on-call techs have access when they need access? It can be expected that a tech will try to keep a file on his/her laptop with the passwords of the systems they would normally need access to -can't stop that- so how do you protect this detail in the event that the laptop is stollen or compromised?
Just looking for comments. Need to figure out what "Best Practices" are for our environment.
Ralph
www.ldfconsulting.com