| Password Protection Standards  |
|   |
| Do not use the same password for your company accounts or other
non-company access (e.g., personal ISP account, option trading,
benefits, etc.). If possible, don't use the same password for various
company access needs.  |
|   |
| Here is a list of "don'ts":  |
| Don't reveal a password over the phone to ANYONE.  |
| Don't reveal a password in an email message.  |
| Don't reveal a password to the boss.  |
| Don't talk about a password in front of others.  |
| Don't hint at the format of a password (e.g., "my family name").  |
| Don't reveal a password on questionnaire or security forms.  |
| Don't share a password with family members.  |
| Don't reveal a password to co-workers while on vacation.  |
| Don't use the "Remember Password" feature of application (e.g., Internet Explorer,
Eudora, Outlook, Netscape.).  |
| Don't write passwords down and store them anywhere in your office.
Do not store passwords in a file or ANY computer system (including Palm
Pilots or similar devices) without encryption or any document card.  |
|   |
| If someone demands a password, refer them to this document or have
them call the Help Desk of the Office of the University Registrar for
assistance at (632) 524-4611, Extension 114, from 0800 to 1800
(Monday to Friday) and from 0800 to 1500 (Saturday).  |
|   |
| If account or password is suspected to have been compromised, report
the incident to Help Desk and change all passwords.  |