INFOSEC - Learning Log #2



This period in INFOSEC, we've focused on Operational Organizational Security. We learned the difference between policies, standards, guidelines and procedures. We learned about Access Controls, Group Policy and Password Policy. I used to think that password were simple. I'd only change it when I was prompted to do so, but then I learned about minimum password age and maximum password age. Like how minimum password age is meant to protect from users. There are some users who are lazy when it comes to memorizing passwords. For example, a student can have a password of student1 and password history of 2 passwords. Without min password age, the student can change his password to student2, then student3, and then back to student1 in the same day - having exceeded the password history count of 2. This defeats the purpose of actually maximum password change and changing the password so that it won't be compromised. I felt sort of guilty while listening to the lecture about password policy because I usually revert to my original password just like other lazy users. Then, we discussed some password policy issues and the importance of password policy. I guess I can say that I've learned my lesson and have learned to be more proactive with passwords.

Comments

Popular posts from this blog

12. - Why the Lord Made Cockroaches

11. - "A Book Is More Than That"

16. - Comments for my Dear Classmates