Policy Number 7.400
Supersedes Policy Dated: June 23, 2003
Effective Date: September 25, 2003
Review Date: September 8, 2006
Title of Policy: Password Expiration Policy
Purpose of Policy: This policy defines the procedures for the expiration of passwords for ITCS enterprise systems. This policy affects the use of ITCS maintained mainframe systems and enterprise servers. This policy has been designed to meet N.C. State audit requirements, governing access to sensitive data.
Person(s) with Primary Responsibilities: The Director of IT Support Services is the primary person charged with administering the ITCS Password Expiration Policy. The systems administrators for the ITCS enterprise systems will be responsible for the notification and expiration of passwords.
Approved:
Chief Information Officer
General Statement: Passwords on ITCS enterprise systems will expire on a regular basis, currently no longer than ninety (90) days, with notification to users via e-mail or system messaging at least 3 times in the two weeks prior to expiration. The only exceptions to this policy are those systems that do not have the capability to force password changes.