[ Policy & Procedures ]
Table of Contents
Password Policy :|: New/Temporary Employee Accounts :|:
Employee Departures Replacing Existing Computers :|:
Purchasing New Computers :|: Web Development Service
Password Policy for all Division of Finance Servers
The Division of Finance at The University of Pennsylvania maintains a network of servers
which contain information which is of a confidential nature and vital to the business continuity of
The University of Pennsylvania. Everyone with access to this network and all associated servers
must be aware of this policy and help do their part in keeping the environment as secure as possible.
The Information Technology and Support department (ITS) assigns a unique id and password for each
user. This id is to be used ONLY by the person to whom it was assigned. Sharing user ids is strictly
prohibited.
Upon creation of a new user id, a temporary password is assigned. The user is given their id and
password on a sealed form and asked to change it immediately. The user must change the password
during their first login. After the password is changed the user should make every effort to keep the
password secret. The password should not be told to anyone. The password should never be written
down. The ITS department is not able to see the password once it has been changed. If the password
is lost the ITS department can set a new one. Each time a new password is set, the user must change
the password at their next logon.
There are certain restrictions on which password can be used. The purpose of these restrictions is
to make it harder for an intruder to guess a user’s password.
A password must be a minimum of eight (8) characters.
A combination of different case letters, numbers, and symbols is recommended.
A user’s id may not be part of the password (i.e. user smith may not make his password dsmith2).
A history of previously used passwords is kept. A user’s password may not be used if it has
been used in the past four (4) months.
A user will be notified to change their password at least every forty-two (42) days.
At no time should a user’s server password be used for anything else particularly a world wide
web site where someone outside of The University will have access to the password.
These policies are in place to maintain security without over burdening the users of our servers.
It is the responsibility of each and every member of the ITS department to uphold these policies
and take appropriate action whenever necessary to maintain the integrity and security of the Division
of Finance servers.
New/Temporary Employee Accounts
Request @ http://footprints.finance.upenn.edu
The ITS Department would like to make the transition for new
employees as easy as possible. In order to do so, ITS requires TWO business days notice to create new accounts.
Employee Departures
Request @ http://footprints.finance.upenn.edu
In order to provide a secure environment for our network and financial files and accounts, the ITS
Department needs ample time to set expiration dates on accounts and network
access. Please notify the ITS Department of all departures a minimum of TWO WEEKS before the employee's last day.
Replacing Existing Computers
Request @ http://footprints.finance.upenn.edu
The ITS Department performs yearly reviews of all existing PC's. It is at this time that
individual PC's are evaluated for replacement or upgrade. If you have a
request for a PC to be evaluated, please fill out a request form. We will make sure it is promptly reviewed.
Purchasing New Computers
Request @ http://footprints.finance.upenn.edu
The ITS Department is responsible for recommending the configuration and purchase of new computers. New
computers are purchased for newly created positions (not
replacement positions). Please allow two to four weeks for
delivery.
Web Development Service
Request @ http://footprints.finance.upenn.edu
ITS Staff can assist in developing and maintaining your department's web site.
|