Question: Assume that you are drafting the User Identification and Authentication section of an IT Security Policy for an organization. Recognizing that: - people do not
Assume that you are drafting the User Identification and Authentication section of an IT Security Policy for an organization. Recognizing that:
- people do not always follow published laws,
- the generally accepted security principal is that passwords should never be written down, and
- research suggests that:
* more than one out of every three enterprise users keep a written record of their passwords (Links to an external site.)Links to an external site.and
* 64% of end users report that they have written down their password at least once (Links to an external site.)Links to an external site..
Should the policy prohibit passwords from being written down or permit passwords being written down in one of the secured formats referenced in the "Is It Okay to Write Down My Passwords? How To Do It Right " article (https://tiptopsecurity.com/is-it-okay-to-write-down-my-passwords-how-to-do-it-right/ )?
Note, please do not make any references to Password Managers.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
