Unified UCSF Enterprise Password Standard
The Unified UCSF Enterprise Password Standard was approved by the UCSF CIO Group on January 7, 2008 and is applicable to all Electronic Information Resources within UCSF, including the UCSF Medical Center. Questions about this standard can be sent to the UCSF CIO Group.

|
Category |
Standard |
|---|---|
|
Maximum Age |
180 Days |
|
Minimum Age |
8 Days |
|
History (changes before repeats allowed) |
8 |
|
Failed logons allowed before lockout |
5 failed attempts |
|
Lockout duration |
15 minutes |
|
Minimum Password Length |
7 |
|
Maximum consecutive character repeats |
2 |
|
Required Characters |
At least 1 character from 3 of 4 character sets: a-z, A-Z, 0-9, symbols ~`!@#$%^&*()_-+={}[]|\:;”’<>,.?/ |
|
Prohibited Patterns |
Easily guessed patterns such as dictionary words, dates, phone numbers, proper names, parts of login name, minor variations on former password, etc. |
This standard should be considered a minimum. Systems that are capable of exceeding these standards should if operationally feasible.
The OAAIS Active Directory implements this standard as part of the Active Directory Password Protocol.
