Arkansas Administrative Code
Agency 016 - DEPARTMENT OF HUMAN SERVICES
Division 14 - Department of Finance (Administrative Services)
Rule 016.14.05-003 - DHS Policy 5002 - DHS Information Systems Password Requirements
Current through Register Vol. 49, No. 9, September, 2024
5002.0.0 DHS INFORMATION SYSTEMS PASSWORD REQUIREMENTS
5002.0.1 This policy states the requirements for creating, securely storing and retrieving access credentials (User Names and Passwords) for all DHS Information Systems. In order to access DHS Information Systems or application, users must authenticate identity by presenting acceptable credentials. Access privileges protected by user credentials can be compromised if the credentials are improperly stored or inadequately safeguarded.
5002.0.2 See DHS Policy 5001, Information Systems Security Access, for related security requirements and a complete definition of terms.
5002.0.3 This policy applies to DHS Users, non-DHS Users, and Systems Administrators in all DHS divisions.
5002.1.0 Definitions
5002.1.1 DHS User: A person, DHS employee, who has been granted access to any DHS information system and is accountable for the security of such access.
5002.1.2 Non-DHS User: A person, not a DHS employee, who has been granted access to any DHS information system and is accountable for the security of such access.
5002.1.3 Access: Upon the presentation of authenticated credentials, permission to use DHS Information Systems.
5002.1.4 Authentication: The automated comparison of presented user credentials with credentials on record for access to DHS Information Systems.
5002.1.5 Credentials: Consists of the combination of a user's User Name (or similar user identifier) and Password.
5002.1.6 DHS Information Systems: DHS Network services (Network access, Email, Internet, etc.), DHS applications (client-server, web-based, mainframe, etc.), or any third-party software legally acquired and installed on the DHS devices for which it was intended. Also includes any computer file, on any device in use by DHS or its agents, that is shared across the DHS network or requires DHS support, or that contains DHS-related information, the privacy of which must be safeguarded.
5002.1.7 System Administrator: Persons designated by DHS's Chief Information Officer to provide technical support and access management for DHS Information Systems.
5002.1.8 Person: A uniquely identifiable and distinguishable human being. A Person is one whose identity has been validated and whose association with DHS has been certified by the division requesting access credentials.
5002.2.0 Safeguarding of Credentials
Private or mission-critical information stored and processed on computer systems must be protected against unauthorized modification, disclosure, or destruction. Users are assigned a unique personal identifier which must be authenticated in conjunction with a valid password before access is granted to DHS Information Systems. Measures must be employed by Users to safeguard credentials with respect to both physical security and access to DHS Information Systems. The structuring of passwords will meet or exceed prevailing state government standards for strong passwords.
5002.3.0 Requirements
DHS Information Systems password construction will conform to the following standards. Password construction standards are also posted on DHS Gold at: http://dhsgold/Passwords.htm
5002.4.0 Disciplinary Action for Violation of Policy
Supervisors should refer to DHS Policy 1084, Employee Discipline, to determine the appropriate disciplinary action for violations of this policy.
5002.5.0 Originating Section/Department Contact
Office of Systems and Technology 1st Floor Donaghey Plaza North P.O. Box 1437, Slot N101 Little Rock, AR 72203-1437 Telephone: 682-0032