• The purpose of this policy is to establish a standard for creation of strong passwords, the protection of those passwords and the frequency of change. Passwords are the most frequently utilized form of authentication for accessing a computing resource. Due to the use of weak passwords, the proliferation of automated password-cracking programs, and the activity of malicious hackers and spammers, they are very often the weakest link in securing data. A poorly chosen password may result in unauthorized access and/or exploitation of Champlain College resources, possibly including the confidential data of students, alumni, applicants, faculty and staff. All users, including contractors and vendors, with access to Champlain College systems are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.

  • This policy applies to all users of computing resources owned or managed by Champlain College. Computing resources include all licensed or managed hardware and software (including telephone equipment) owned by the College, and use of the College network via a physical or wireless connection, regardless of the ownership of the computer or device connected to the network.

    Specific users bound by this policy include:

    • Champlain College students, including undergraduate, graduate, online students and alumni
    • Faculty, including full-time, part-time and retired faculty members
    • Staff, including full-time, part-time, temporary and retired workers
    • Guests
    • Members of 3rd-party organizations given access to Champlain systems, such as vendors, contractors or consultants
  • All passwords for Champlain College systems and applications (e.g., email, web, desktop computer, etc.) should be strong passwords and follow the standards listed below. In general, a password’s strength will increase with length.

    Use of multi-factor authentication is required for all Champlain College systems and all accounts unless technically unavailable.

    3.1 Password Creation

    Champlain College has adopted NIST’s guidelines for password complexity. All passwords must meet the following minimum standards, except where technically infeasible (as agreed upon by the Chief Information Officer).

    • Passwords should be 14 – 60 characters long. Longer passwords are inherently more secure because it takes hackers longer to guess them when employing a brute force method.
    • Sequential (e.g., “1234”) or repeated (e.g., “aaaa”) characters may not be used.
    • Passwords found in any public lists of breached passwords or in lists of commonly used passwords must not be used.
    • Champlain College may periodically check breached password lists against college accounts for validity. Any valid passwords that are found to be in a list of breached passwords will need to be changed immediately.
    • Passwords may not include components of the user’s name or login name.
    • To help prevent identity theft, personal or financial information such as Social Security or credit card numbers must never be used as a user ID or a password.

    3.2 Password Management

    • It is required that passwords be changed at least every 12 months, unless a shorter change interval is mandated (such as computers subject to the PCI Data Security Standard (those that take credit cards), which require passwords to be changed every 90 days).
    • Additional password changes may be required in the event it is suspected that a password has been compromised.
    • Passwords used for administrative accounts or any account with elevated privileges on a system must be changed at least annually.
    • All passwords are to be treated as Confidential Information as defined in Champlain College’s Data Classification Policy and should therefore never be written down or stored electronically unless properly encrypted.
    • Only use the “Remember Password” feature of a software application, if you are
      assured that the feature stores your credentials in a secure, encrypted fashion. Modern web browsers offer minimal password managers that encrypt your password with your sign-in credentials. For this reason, you are strongly advised to never store your password if you are on a public kiosk, unencrypted smartphone, unencrypted laptop or public lab computer.
    • Unencrypted passwords should never be inserted into email messages or other forms of electronic communication. Communicate passwords to people verbally over the phone, in person, or via an encrypted document.
    • Do not use your Champlain College password for any other systems external to Champlain (e.g., 3rd-party vendor sites, personal Web accounts, etc.). Should those systems become compromised, someone could use those credentials to access your Champlain account.
    • Passwords should be different for each separate system that uses a password.
    • Individual passwords must not be shared with anyone, including administrative assistants, IS personnel or family members. Necessary exceptions may be allowed with the written consent of the Chief Information Officer (CIO). The CIO will review the request and, if in agreement, then request approval from either the President or the Provost of the College.
    • The use of shared accounts shall be controlled through means other than a password shared amongst many staff members. For example, a shared Google Mail account or calendar will be accessed through account delegation.
    • Shared passwords used to protect network devices, shared folders or files require a designated individual to be responsible for the maintenance of those passwords, and that person ensures that only appropriately authorized employees have access to the passwords.
    • Any user suspecting that their password may have been compromised must immediately change the password and report the incident to the Champ Support Help Desk.
    • Bypassing password security to access a Champlain College system is strictly forbidden.
    • Champlain College may perform password cracking or guessing on a periodic or random basis. If a password is guessed or cracked during one of these scans, the password owner will be notified and be required to change it immediately.
    • Password cracking or guessing on College systems by unauthorized users is strictly forbidden.

     

    3.3 Changing your Password

    To change your password, use your web browser to go to welcome.champlain.edu.

  • Any exceptions to this policy must be approved by the Chief Information Officer.

  • Any individual found to be in violation of this policy shall be subject to appropriate disciplinary action, up to and including termination of employment or expulsion from enrollment at the College. Individuals are also subject to federal, state and local laws governing many interactions that occur on the Internet. These policies and laws are subject to change as state and federal laws develop and change. Any individual found to be in violation of this policy shall be subject to appropriate disciplinary action, up to and including termination of employment or expulsion from enrollment at the College. Individuals are also subject to federal, state and local laws governing many interactions that occur on the Internet. These policies and laws are subject to change as state and federal laws develop and change.