OPERATIONAL POLICY
NUMBER: IS.103
TITLE: Password Standard
DATE: October 8, 2024
REVISION:Â
DEPARTMENT:Â Information Security
Authorized:Â Rafael Espinosa, Chief Information Officer
Assigning unique individual logins and requiring password protection is one of several primary safeguards employed to restrict access to Santa Clara University networks, systems, applications, and data. If a password is compromised, inappropriate access might be obtained by an unauthorized individual. Individuals with SCU accounts are responsible for safeguarding against unauthorized access to their account, and as such, must conform to this policy in order to ensure passwords are kept confidential and designed to be complex and difficult to guess. The parameters in this policy are designed to comply with relevant legal and regulatory standards, including but not limited to GLBA and PCI-DSS
Applies to all students, faculty, staff, contractors, consultants, temporary employees, guests, volunteers and all other entities or individuals with access to Santa Clara University network, cloud, or data resources.
The following parameters indicate the minimum requirements for passwords for all accounts (except for those defined in Privileged & Service Accounts below):
Information Services reserves the right to reset account passwords of any account suspected or determined to have a compromised password.
internal policies to SCU that should be considered to ensure ensure behavior is consistent. Optional.
Questions or comments to is-policy@scu.edu
Effective Date: October 8, 2024
Last Reviewed:Â October 8, 2024
Next Scheduled Review: October 8, 2025
IS.003 Â Password Standard, 2024.10.08