BlackBerryForums.com : Your Number One BlackBerry Community      

»Sponsored Links




Closed Thread
 
LinkBack Thread Tools
  (#1 (permalink)) Old
Jim Bond Offline
Thumbs Must Hurt
 
Jim Bond's Avatar
 
Posts: 79
Join Date: May 2005
Location: Toronto
Model: 8700
Carrier: Bell
Default IT Policies and security - 07-19-2006, 08:36 AM

We are having discussions about how to set up BB security using policies on the BES server.

I've been asked to see what some of the "best practices" on passwords are, and what reasoning would be behind forced password changes etc.

What are your own companies doing with in this area?

What reference materials are available that describe best practices in relation to password policies on Blackberry's etc...

Thanks!


Crackberry Neophyte
   
Sponsored Links
Please Login or Register to Remove these Advertisements!

  (#2 (permalink)) Old
d_fisher Offline
BBF Moderator
 
d_fisher's Avatar
 
Posts: 4,469
Join Date: Oct 2005
Location: Columbus, OH
Model: 8100
OS: SID 6.7
PIN: KS All Out
Carrier: T-Mobile
Default 07-19-2006, 08:46 AM

At my employeer, a password is required (non-expiring) with a timeout of 60 minutes. No complexity requirements other than ones the handheld enforces (ie. 1234, abcd, etc.)


Doug

Remember, please try searching first!

Need a screenshot? ... Like JavaLoader?
Try using BBscreen .....Use JL_Cmder!
or BBScreenShooter!

   
  (#3 (permalink)) Old
jinksPadlock Offline
Knows Where the Search Button Is
 
Posts: 36
Join Date: Jul 2006
Model: 7290
Carrier: T-Mobile
Default 07-19-2006, 10:42 AM

It all depends on the sensitivity of your data...

Here are good references for Gov or private sector dealing with Gov standards.

csrc.nist.gov/publications/nistpubs/800-53/SP800-53.pdf
csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf
   
  (#4 (permalink)) Old
juwaack68 Online
BBF Moderator
 
juwaack68's Avatar
 
Posts: 9,824
Join Date: Oct 2005
Location: Tulip City - MI
Model: 8330
OS: 4.iforgot
PIN: ch me
Carrier: Sprint - 2 Curves
Default 07-19-2006, 11:18 AM

We use a forced password, minimum 6 characters, must have 1 letter and 1 number. Users cannot disable the password, but are able to set the timeout to the maximum of 1 hour.



Looking for answers? Try doing a Search first.

LOTS of answers here: Main Page - BlackBerryFAQ
   
  (#5 (permalink)) Old
Jim Bond Offline
Thumbs Must Hurt
 
Jim Bond's Avatar
 
Posts: 79
Join Date: May 2005
Location: Toronto
Model: 8700
Carrier: Bell
Default 07-19-2006, 12:42 PM

Thanks for the replies so far... Boy, that government publication will make good bedtime reading!! LOL
To pontificate profusely... On the issues of security, do most people feel that a forced password change is a good thing?
How about "hacking" of a network with a blackberry? Anyone know how / if it's been done?


Crackberry Neophyte
   
  (#6 (permalink)) Old
jinksPadlock Offline
Knows Where the Search Button Is
 
Posts: 36
Join Date: Jul 2006
Model: 7290
Carrier: T-Mobile
Default 07-19-2006, 12:55 PM

Yeah, that stuff will knock you out faster than NyQuill.

The main point is that since BB's have a lock and reset after 10 failed attempts the password has a stronger entropy. Meaning that even if you have a shorter password and a longer time between forced password changes it can still meet levels 1 and 2 for low to moderate impact systems.

There are some stipulations if you are using content protection, but otherwise I would go with around 8+ chars w/ 1 special and force reset every 90 days or so. Although twice a year would probably work too.

I've never read about any specific hacks, but if you are using MDS there are some pretty big concerns. Once again it really depends on the sensitivity of the data you operate with.
   
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On






Copyright © 2004-2008 BlackBerryNews.com, BlackBerryFAQ.com, BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of Research In Motion Limited.
Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.1