Password Policy
POLICY #: CR 26-3
DATE OF BOARD OF TRUSTEES APPROVAL: 9/28/2026
RESOLUTION #: 26-3
Purpose:
This policy outlines password management requirements for Herkimer County Community College (HCCC) user accounts. Passwords are a common means of authenticating a user’s identity when accessing information systems. Password standards need to be implemented to ensure all authorized individuals accessing College Information Technology (IT) resources follow proven password management practices. These password rules must be mandated by automated system controls whenever possible.
Scope:
This policy and all policies referenced herein, shall apply to all members of the College community, including employees, students, alumni, authorized guests, and independent vendors who use, access, or otherwise employ, locally or remotely, the College’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Definitions:
- IT Resources: Includes computing, networking, communications, application, and telecommunications systems and infrastructure; hardware and software; data and databases; personnel; procedures; physical facilities; cloud-based and Software as a Service (SaaS) vendors; and other related materials, services, and resources.
- Suspicious Login Attempt Behavior: Login activity or patterns identified by IT as potential indicators of an attempted or actual account compromise. Examples include an excessive number of failed login attempts within a defined period, repeated authentication failures from unusual locations or devices, or other activity consistent with a brute-force or password-guessing attack.
HCCC Password Standards:
To ensure the proper management and protection of passwords, the following standards must be implemented where technically feasible:
- Passwords must not be the same as the user ID and must not contain the user’s name or other readily identifiable portions of the user’s identity.
- Passwords must be a minimum of 13 characters in length.
- Where technically feasible, password selections must be checked against a prohibited list of known, commonly used, compromised, or otherwise unacceptable passwords.
- Passwords must not reuse any of the account’s previous five (5) passwords.
- User account passwords must be kept confidential and must not be shared with or disclosed to another user.
- Passwords should not be written down or stored in an unsecured location.
- Temporary passwords must be changed upon the user’s first successful login.
- Accounts must be subject to appropriate lockout controls following the detection of suspicious or repeated unsuccessful login attempts. Unless otherwise required by the system or security configuration, the account lockout period will be 15 minutes or until reset by an authorized individual.
- A password reset must be required when activity or behavior indicates that an account may have been compromised.
- The identity of a user requesting a password reset must be verified before the reset is performed.
- Shared or generic accounts used for privileged or administrative purposes must have their passwords changed at least at the end of each academic year and whenever an individual with knowledge of the password leaves the College or no longer requires access to the account.
- Shared or generic accounts should be avoided where technically feasible. Where such accounts are necessary, their use must be appropriately authorized, documented, and monitored.