Tower

GatorLink Password Management Policy

(Effective May 5, 2004)

The University of Florida (UF) is committed to a secure information technology environment in support of its missions. With the implementation of new integrated, real-time computer systems and single sign-on accessibility via the myUFL portal, the need for a strong password policy is greater than ever.

The GatorLink username and password is the University standard username and password for authentication for all new information systems. The University uses a role-based approach for providing access to these systems. Each person affiliated with UF has one or more security roles. Each security role has an associated password policy. If an individual has several roles, with conflicting password policies, the “strongest” policy applies.

This policy is guided by the following principles:

GatorLink passwords and security roles—and the resulting association of password policy to a user—are held in the PeopleSoft Enterprise Portal system (myUFL) and managed by UF Bridges.


Appendix Table A: GatorLink Password Policy Matrix

P1 : Entry. For example: Vendors, guests, student applicants, HR applicants

P2 : Low. Example: Access to information only about yourself.

P3 : Medium. Example: Access to information about others. Provide data at unit level.

P4 : High. Example: Access to information at the institutional level

P5 : Rigorous. Example: Control institution systems.


Attribute

P1

P2

P3

P4

P5

1. Minimum length of password

8

8

8

9

9

2. Password is character checked

Yes

Yes

Yes

Yes

Yes

3. Maximum age of password (in days)

365

365

180

90

90

4. Days of daily expiration warnings

14

14

14

14

14

5. Password minimum age for reset (in days)

1

1

1

1

1

6. Password uniqueness/history

200

200

200

200

200

7. Failed attempts before lockout

20

20

20

20

20

8. Lockout duration in minutes

30

30

30

30

30

9. May reset via Self-service web

Yes

Yes

Yes

No

No

10. May reset via Help Desk phone

Yes

Yes

Yes

No

No

11. May reset In person

Yes

Yes

Yes

Yes

Yes

12. Must read AUP on reset

Yes

Yes

Yes

Yes

Yes

13. Must take quiz once per year

No

Yes

Yes

Yes

Yes

14. Must complete security class before account is issued

No

No

No

Yes

Yes

15. Must use 2-factor authentication

No

No

No

No

Yes

16. Account is expired if password is cracked

No

No

No

Yes

Yes

Attribute Notes:

OIT Units

Chief Information Officer , Academic Technology, Computing and Networking Services , Network Services, Telecom

Services

Students, Faculty, Staff

Committees

IT Advisory Committee, Academic Technology, Data Infrastructure, High-Performance Computing, Network Infrastructure, Information Security Management, Ad Hoc

Projects

UF Exchange, High Performance Computing, AT Grid, Active Directory Project, Microsoft Campus Agreement, more...

Policies

Acceptable Use (AUP), IT Security, IT Strategic Plan, Disabled Access Computing Policy, more...

System Status

Bridges Status, CNS Reported Issues, Gatorlink Mail, ISIS, Outgoing Mail, Network Status, Webadmin Sites, Webmail

Training

Students, Faculty, Staff, Other Resources

Topics of Interest

Charging for Dial Up Services, Gatorlink Eligibility, Email/Gatorlink Configuration, Connecting to UF , IT Reports

Text-only Version

Search: