1.12.20.21 NMAC

Section 21. User Password Management

Last amended: 2010Year: 2010Length: 380 wordsOfficial source
Password protocols shall be developed consistent with state standards and implemented to ensure all authorized individuals accessing agency resources follow 1.12.11 NMAC Enterprise Architecture. Such password protocols shall be mandated by automated system controls whenever possible. Password protocols should include, but not be limited to: A. compliance with 1.12.11.16 NMAC (Security Password rule); B. prohibiting the storage of passwords in clear text; C. prohibiting the use of passwords that could be easily guessed or subject to disclosure through a dictionary attack; D. direction for keeping passwords confidential; E. prohibiting any and all password sharing; F. directing users to change passwords at regular intervals; G. direction for changing temporary passwords at the first logon; H. enforcing the implementation standard password formats to include a mix of alphabetic, numeric, special, and upper/lower case characters; I. automated logon processes which must be approved by agency CIO; J. implementing state password standards and protocols on agency computing resources; and K. verifying proper enforcement of password management by the agency during an annual independent risk assessment. [1.12.20.21 NMAC - N/E, 04/14/2010] 1.12.20.22 PROHIBITION OF USE OF PERSONAL COMPUTING DEVICES ON STATE EQUIPMENT OR SYSTEMS: A. Connecting any computing device not owned by the state of New Mexico to a state network or to any state computing device is prohibited unless authorized in writing by the agency CIO. B. Installation of any software, executable or other file to any state computing device is prohibited if that software, executable, or other file was downloaded by, is owned by, or was purchased by an employee or contractor with his or her own funds. C. Installation of downloaded software, executables, or other files to any state computing device is prohibited when downloaded or installed by an employee or contractor for personal use utable or other file to any state computing device is prohibited if that software, executable, or other file was downloaded by, is owned by, or was purchased by an employee or contractor with his or her own funds. C. Installation of downloaded software, executables, or other files to any state computing device is prohibited when downloaded or installed by an employee or contractor for personal use. Downloaded software, executable, or other files include, but are not limited to: SKYPE, music files or other software, and personal photos.
1.12.20.21 NMAC: Section 21. User Password Management | Justis AI