NRC-Pwd-Warn-Banr-Guid-Attachment VI.pdf

PDF 90 KB Posted

Attached to
New Reactor Control Room Simulator and Improving the General Electric Simulator Federal contract opportunity
Solicitation number
RS-38-10-702
Issued by
Nuclear Regulatory Commission Central Office

About this file

NRC Password and Warning Banner Guidance - Attachment VI

View the file

Other files for this federal contract opportunity

Other files attached to New Reactor Control Room Simulator and Improving the General Electric Simulator, newest first.
File Type Posted
RS-38-10-702.doc DOC document
RS-38-10-702-Amendment No. 03.pdf PDF
CS_Information_Protection_Policy - Attachment II.pdf PDF
SF30-Amendment No. 02.PDF PDF
RulesOfBehavior - Attachment VII.pdf PDF
GESampleSubr- Attachment - VIII.pdf PDF
LaptopPolicy - attachment V.pdf PDF
General_Laptop_Configuration_Std - Attachment IV.pdf PDF
DataAtRestEncryptionPolicy - Attachment III.pdf PDF
RS-38-10-702_GEQuestions12-15-2009.doc DOC document
GEIo- Attachment I.pdf PDF
RS-38-10-702-Amendment No. 01.pdf PDF
RS-38-10-702 Solicitation.PDF PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 1

13 June 2003

VERSION 1.1

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 2

NRC Password and Warning Banner Guidance

2 13 June 2003

Table of Contents

1. Introduction 1

1.1 Background 1

1.2 Objectives 1

1.3 Scope 1

2. Password Guidance 2

2.1 Password Deficiency Finding 2

2.2 Password Discussion 2

2.3 MD and Handbook 12.5 Requirements 3

2.4 Recommended Password Parameter Settings 4

2.5 Password Compliance 6

3. Warning Banner Guidance 6

3.1 Warning Banner Deficiency Finding 6

3.2 Warning Banner Requirement 6

3.3 Warning Banner Compliance 7

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 3

3 13 June 2003

1. Introduction

1.1 Background

In order to satisfy the Government Information Security Reform Act (GISRA) requirements for Fiscal Year 2002, The United States Nuclear Regulatory Commission (NRC) hired Richard S.

Carson and Associates, Inc. (Carson) to perform an independent evaluation of NRC’s Information Security Program. This effort produced a consolidated list of 28 recommendations to the Executive Director of Operations (EDO). Many of these recommendations deal with the security of individual NRC information systems. The two specific recommendations addressed by this guidance are:

1. Implement password controls on all NRC systems

2. Display a warning banner prior to logging on to any NRC system or server

NOTE: NRC is currently executing the "NRC System Security Baseline Implementation Plan," which involves the implementation of secure system configurations (Benchmarks) for all NRC systems. A separate Benchmark was developed/selected for each NRC operating system. The Benchmarks vary slightly in specific password recommendations; likely due to the fact that Benchmarks were written by different groups of experts and because each operating system has different password configuration capabilities. Some of the individual Benchmarks’ password guidance may be more "strict" than this guidance, however, the recommendations in this guidance should not conflict with the Benchmarks (this document can be thought of as the lowest common denominator for secure password guidance). This document presents a minimum level of password settings that should be implemented and enforced on all NRC information systems.

1.2 Objectives

The primary objective of this document is to provide guidance on what NRC systems need to satisfy password and warning banner requirements presented in Management Directive (MD) and Handbook 12.5 - "NRC Automated Information Systems Security Program." An additional objective of this document is to provide guidance on how to strengthen NRC passwords through the establishment of specific password parameter recommendations and through the establishment of a process to verify that sufficiently secure passwords are being selected by users and enforced by NRC information systems. A process to verify warning banners are appropriately displayed when a person logs into an NRC information system is also presented.

1.3 Scope

The GISRA finding referenced above recommended "Implement password controls on all NRC systems." In a meeting between OCIO staff and OIG staff in October 2002, clarification was obtained that specified that this recommendation primarily applied to the NRC local and wide area network (LAN/WAN) infrastructure systems.

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 4

4 13 June 2003

This guidance is directed at ensuring an official NRC warning banner is displayed before an individual logs directly onto any system connected to the NRC LAN/WAN, whether the individual is logging onto the network or the system itself. This guidance is also directed at ensuring MD12.5 password requirements are being implemented on these same systems.

This guidance does not address access to specific NRC applications, web pages, or databases.

It only addresses the initial "logging on" to a specific NRC system or the NRC network.

2. Password Guidance

2.1 Password Deficiency Finding

The Carson report "Independent Evaluation of NRC’s Information Security Program As Required by the GISRA For Fiscal Year 2002," Addendum, Chapter 5 - Information Security Controls Testing, indicated that some of the NRC systems evaluated had problems in the area of identification, authentication, and password management.

Carson security controls testing specifically found:

• On several servers, users are not forced to change their passwords every 90 days

• On several servers, the password length and format are enforced only by written policy, even though the operating system has the capability to enforce length and format restrictions

• Trivial passwords such as "aaaaaa" were allowed on some systems; no complexity enforced

NOTE: MD 12.5 is currently being updated. There are a few differences in the password policies between the version of MD 12.5 utilized during the Carson information security evaluation and the current draft version of MD 12.5. This document is written to support the updated (newer) version of MD and Handbook 12.5.

2.2 Password Discussion

MD and Handbook 12.5 specify minimum password requirements for NRC systems and users.

In addition to MD and Handbook 12.5 requirements, there are a few other password parameters that should be set and enforced. These other password parameters play an important role in ensuring sufficiently secure passwords are selected and utilized.

It is important to note that operating systems have differing capabilities to set and enforce various password parameters. Some of the recommended password parameter settings will only be applicable for specific operating systems. Some of the password parameter settings may be applicable to all operating systems, but may only be enforceable by specific operating systems.

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 5

5 13 June 2003

A goal of this password improvement initiative is to implement all recommended password parameters that are applicable to particular operating system and to have the operating system enforce password parameters it is capable of enforcing. In circumstances where password parameters are not enforceable through the operating system, written policy and user education should be exercised. The password "evaluation" process, discussed in a later section, will be utilized to ensure all NRC information systems and users are complying with password guidance contained in MD and Handbook 12.5 and this document.

2.3 MD and Handbook 12.5 Requirements

MD and Handbook 12.5 contain minimum password requirements for NRC systems and users.

These minimum password criteria should be enforced on all NRC information systems identified in the scope of this document. Handbook 12.5 specifies the following required criteria for NRC passwords:

• Each User ID shall have an associated user-selectable password and each NRC system must have the password mechanism enabled to authenticate the claimed identity of the user

• Passwords should be a minimum of six characters in length. Acceptable password characters should include alphabetic and numeric characters (or special characters such as $, #, @). Passwords may or may not be case-sensitive

• New passwords should differ from the replaced password by at least two characters

• The system should automatically force all users to change passwords at least every 90 days. The system should automatically lock out a user who violates this procedure

• A mechanism/process should exist to disable User IDs after 90 days of inactivity

• The system should be set to end a logon session after three unsuccessful logon attempts

• Passwords should never be displayed as clear text whether printed or displayed on a screen

• Passwords should never be written down, stored in clear-text on computer media storage, or shared with others

• Passwords should be stored in one-way encrypted form

• An NRC HQ LAN/WAN system should have the screensaver password protection option set for 15 minutes

• All default system passwords should be changed

• Users should protect all User IDs and associated passwords issued to them and should not disclose the passwords to anyone for any reason

The password criteria specified above are the minimum password criteria required by MD 12.5.

The next section includes a list of recommenced "best practice" guidance for passwords in an easy to use tabular format.

2.4 Recommended Password Parameter Settings

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 6

6 13 June 2003

As stated earlier, MD and Handbook 12.5 provide the minimum NRC password criteria. A few other recommended password criteria are not included in 12.5. These "additional" password criteria further enhance NRC password security.

The table below contains all 12.5 password criteria and a few other recommended password criteria. The primary goal of this password improvement initiative is to implement all recommended password parameters that are applicable to a particular operating system and to have the operating system enforce password parameters it is capable of enforcing. In circumstances where password parameters are not enforceable through the operating system, written policy and user education should be exercised. NRC System Administrators should attempt to adopt as many of the following password criteria possible/permissible; always considering the operating environment and mission of each NRC system.

The password parameter settings listed in the table below contains the items which systems and passwords will be evaluated against, as discussed in the next section on password compliance.

NRC RECOMMENDED PASSWORD CRITERIA

Password

Criteria Required By

MD 12.5

Recommended

Setting Password Criteria

Discussion Password Policy Minimum Password Length

Yes 6 Character Minimum

Minimum password length can be enforced by Windows, Novell, and

UNIX

Minimum Password Age

No 1Day - if operationally feasible

1 Day Setting will prevent users from immediately changing passwords back to the one they were previously using.

Can be enforced by Windows, Novell, and some flavors of UNIX.

Maximum Password Age

Yes 90 Days Maximum password age can be enforced by Windows, Novell, and

UNIX

Password History Yes (marginally)

MD 12.5 states "new passwords should differ from the replaced password by at least 2 characters"

Set system to remember, and not allow re-use of, last

10 passwords (if capability exists)

Most operating systems do not have the capability to enforce 2 characters different from previous password.

Windows, Novell, and some flavors of

UNIX do have the capability to remember the last "so many" passwords and not allow re-use.

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 7

7 13 June 2003

Password Complexity

Yes (marginally)

MD 12.5

definition of complexity is not very strict "the password should include numbers and characters"

Password should consist of 3 out of 4 of:

(1) lowercase letter

(2) uppercase letter

(3) number

(4) special character

** May use a less strict complexity rule

Windows complexity definition consists of password containing 3 out of 4 of:

(1) lowercase letter, (2) uppercase letter, (3) number, (4) special character Windows can enforce this complexity rule; it must be enforced by written policy for Novell and UNIX. ** It is OK to adopt a looser definition of password complexity, but the policy should require more than just numbers and characters

Store Passwords using reversible encryption

Yes Passwords should be stored in one-way encrypted form

One-way encryption capability exists in Windows, Novell, and UNIX

Account Lockout Policy Account Lockout Duration

No 1Hour Windows and Novell have capability.

Most UNIX’s do not have this capability Account Lockout Threshold

Yes 3 attempts MD 12.5 states "system should be set to end a logon session after 3 unsuccessful logon attempts."

Reset Account Lockout After

No 1 Day Windows and Novell have capability.

Most UNIX’s do not have this capability

2.5 Password Compliance

Sufficiently secure passwords are a vital component of a secure NRC information system infrastructure. The only way to ensure sufficiently secure passwords are being chosen and utilized by NRC system users is by performing password "evaluations."

Password "evaluations involve inspecting password/account configuration settings and also acquiring copies of password files from NRC systems and running software against these password files to "crack" or determine how secure each individual password is. Password "evaluations" will be run on a recurring basis to ensure NRC information system users are complying with policy and recommendations.

Password evaluations reveal sensitive user passwords. Password evaluations can only be conducted by the NRC LAN/WAN ISSO or an individual designated by him/her. The tools utilized for password "evaluations" must be authorized by the NRC LAN/WAN ISSO and must be in compliance with the document "Guidelines for the Use of Vulnerability Scanning and Password Checking Software," which can be found on the Network Security Technical

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 8

8 13 June 2003

Guidelines web page.

In instances were user passwords are found to be "poor" or not in compliance, the first effort will be to determine what changes/improvements can be made to the operating system to enforce better password selection. If this effort is found to not be sufficient, individuals found to have "poor" passwords will be notified by email to change their password to a more secure password and reminded what comprises a secure password.

3. Warning Banner Guidance

3.1 Warning Banner Deficiency Finding

The Carson report "Independent Evaluation of NRC’s Information Security Program As Required by the GISRA For Fiscal Year 2002," Addendum, Chapter 5 - Information Security Controls Testing, indicated that warning banners were being displayed prior to users logging in to the NRC LAN/WAN, but that a large number of servers evaluated did not display a warning banner prior to the login process. MD and Handbook 12.5 clearly state the requirement for a warning banner prior to logging into an NRC system.

3.2 Warning Banner Requirement

For the sake of completeness, the requirement for warning banners for NRC systems is presented below (from Handbook 12.5 Section 9).

NRC managers should ensure that all users are aware of their responsibilities for proper use of the system and the prohibitions against misuse of the system and that their activities on the system are subject to monitoring.

Systems shall be configured to display the following warning banner to users upon first accessing NRC automated information resources:

USE OF THIS COMPUTER CONSTITUTES A CONSENT TO MONITORING

This computer system is for official or authorized use only. Federal computer systems are subject to monitoring for maintenance, to preserve system integrity and security, and for other official purposes. You should not expect privacy, nor protection of privileged communication with your personal attorney, regarding information you create, send, receive, use, or store on this system.

If monitoring reveals possible evidence of violation of criminal statutes, this evidence and any related information, including your identification, may be provided to law enforcement officials, including the Office of the

Eugene Burdine - NRC Password and Warning Banner Guidance.wpd Page 9

9 13 June 2003

Inspector General. Anyone who violates security regulations or makes unauthorized use of Federal computer systems is subject to criminal prosecution and/or disciplinary action.

UNAUTHORIZED ACCESS PROHIBITED BY LAW - TITLE 18 U.S. CODE SECTION 1030

Public Law 99-474 provides that anyone who accesses a Federal computer system without authorization, and by means of such conduct obtains, alters, damages, destroys, or discloses information, or prevents authorized use of information on the computer, shall be subject to fine or imprisonment, or both.

3.3 Warning Banner Compliance

Warning banners are an important component of a secure NRC information system infrastructure. To ensure NRC systems are correctly configured to display the official NRC warning banner (above) to users upon first accessing NRC automated information resources, the NRC LAN/WAN ISSO, and individuals designated by him/her, will perform warning banner "evaluations" of NRC systems.

Warning banner "evaluations" will consist of "randomly sampling" computer systems throughout the NRC infrastructure and confirming the official NRC warning banner is displayed before a person "accesses" or logs on to the system/network. This "evaluation" includes testing of the logging onto the servers themselves. System administrators responsible for systems that do not comply with the NRC warning banner requirement will be informed of the finding and requested to comply as soon as possible. After the warning banner issue is sufficiently resolved, the responsible system administrator must respond, via email or letter, to the NRC LAN/WAN ISSO stating the issue is corrected. The NRC LAN/WAN ISSO, or designate, will then re-evaluate the system/network to ensure the system/network is in compliance.

In instances where the official NRC warning banner can not be implemented/displayed on a system/server monitor, the warning banner must be visibly displayed, on the console itself, in the form of a sticker or piece of paper that contains the official NRC warning banner notice.

File details come from the government source that posted it. Updated .