Skip to content
BOL Conferences
Thread Options
#1283906 - 11/09/09 10:45 PM Online Password expire requirement
remerson Offline
New Poster
Joined: Nov 2006
Posts: 21
I know I should know this but at the moment....it's just not coming to me!

Is there a regulation stating what requirements must be met for Online banking procedures involving the password expiration? We have ours set to expire every 90 days but have double authentication in place with security questions. So do we really need to have the password expiration? Some banks don't require it so I am trying to figure out why ours was set up that way....filling in the shoes of someone before me. smile

Would appreciate hearing from anyone as I need to bring this up to the Officer's and then Directors if we want to change it and realize the risk involved to our customers.

Thanks!

Return to Top
eBanking / Technology
#1285319 - 11/12/09 03:42 PM Re: Online Password expire requirement remerson
YoungAndEager Offline
100 Club
Joined: Apr 2009
Posts: 135
Indiana
I use three banks, one small community bank, one large national bank, and one online only bank.

None of the three mandate password changes for online banking.
_________________________
"...muffins are just bald cupcakes." -- Jim Gaffigan

Return to Top
#1285321 - 11/12/09 03:44 PM Re: Online Password expire requirement YoungAndEager
Skittles Offline
10K Club
Skittles
Joined: Sep 2002
Posts: 13,965
TN
Ours expire every 180 days.
_________________________
My Opinions Only

Return to Top
#1285875 - 11/13/09 02:42 AM Re: Online Password expire requirement Skittles
Andy_Z Offline
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,754
On the Net
FFIEC guidance tells you your password needs to change periodically, 90 days, but there is no such requirement for your customers. You may opt to impose one.

Two schools of thought are that it may prompt the sticky note on the monitor with the password, and it may upset your customer, BUT it certainly makes it safer for online banking. Educating your customer as to why this is so may make it more palatable. I also think it will force them to have a different IB password than they use for Facebook. I used to be against such a requirement. After helping write Tech Talk and seeing more breach stories, my opinion has changed. The threat environment is greater than it was a few years ago.

http://www.bankersonline.com/technology/techtalk.html (You can see the current copy here, link to Archives, and the free subscription.)
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top
#1286114 - 11/13/09 04:25 PM Re: Online Password expire requirement Andy_Z
Ready to Retire Offline
Diamond Poster
Joined: Aug 2005
Posts: 2,313
Living in the land of Oz
Our examiners made us put in a password change for our Internet Banking and our telephone banking product. But I don't remember what the timeframe is.

Return to Top
#1292187 - 11/24/09 03:30 PM Re: Online Password expire requirement Ready to Retire
Passing storm Offline
100 Club
Joined: Aug 2005
Posts: 111
Here and Now
We post a recommendation to change passwords on our On-Line banking site but do not force password changes
_________________________
Don't believe everything you think

Return to Top

Moderator:  Andy_Z