Skip to content
BOL Conferences
Thread Options
#211650 - 07/15/04 08:00 PM 90-Day Password Changes
michellecc Offline
100 Club
michellecc
Joined: Sep 2003
Posts: 128
Southern New England
Good afternoon.

Where can I find FDIC guidance on changing passwords every 90 days. We have had several complaints from our internet bank customers that they have to change their password every 90 days. We want to quote language from the regulators. Thank you.

Return to Top
eBanking / Technology
#211651 - 07/15/04 08:51 PM Re: 90-Day Password Changes
JacF Offline

Power Poster
Joined: Nov 2001
Posts: 6,719
PA
I don't know of any officie written guidance, but we also require 90 day password changes per recommendations from our FDIC examiners.

Return to Top
#211652 - 07/15/04 09:20 PM Re: 90-Day Password Changes
MackenzieS Offline
Diamond Poster
MackenzieS
Joined: Jul 2002
Posts: 1,722
Oklahoma
Check out the FFIEC's IT Examination manual. On page 22 of the manual it states:

"The length, character set, and time before enforced change are important controls for pass phrases as well as passwords".

They do not specifically require a 90 day interval, however, from all the seminars I have attended and from all the materials I have read, this appears to be an "industry standard".

FFIEC manual

Return to Top
#211653 - 07/15/04 11:31 PM Re: 90-Day Password Changes
Andy_Z Offline
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,750
On the Net
In many cases these are just recommendations and sometimes I have heard them expressed for the bank's systems, not customers.

While this is a safer route to follow, I always worry that it will lead to the sticky note stuck on the monitor. I think it may also be relaxed if you have stringent controls in place on the number and variation of characters in the first place, such as the inability to use a dictionary word and the requirement to use one or more non-alphanumeric characters.

Bottom line, if it is a written rule, and it could be, I haven't seen it. So I think it is urban legend at this point.
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top
#211654 - 07/16/04 01:27 PM Re: 90-Day Password Changes
Anonymous
Unregistered

Thank you.

Return to Top
#211655 - 07/16/04 02:07 PM Re: 90-Day Password Changes
Wore Out Offline
Platinum Poster
Wore Out
Joined: Dec 2003
Posts: 543
Kentucky
We recently went through an FDIC exam and, though it was not technically in print, they did scrutinize closely the internal password controls and changes. Part of the summary of the exam were those recommendations for changes to be made based on access level of sensitive information (i.e. Administrators were recommended to change a minimum of every 30 days, loans 60 days, retail personnel 90 days, etc.) Hope this helps
_________________________
Not even close to being legal advice....I have a bridge for sale too!

Return to Top
#211656 - 07/16/04 02:24 PM Re: 90-Day Password Changes
JacF Offline

Power Poster
Joined: Nov 2001
Posts: 6,719
PA
Qtip,
Did they say anything about customer passwords for Internet banking?

Return to Top
#211657 - 07/16/04 02:33 PM Re: 90-Day Password Changes
Wore Out Offline
Platinum Poster
Wore Out
Joined: Dec 2003
Posts: 543
Kentucky
No, but we don't have internet banking at this time. They suggested to call our field office prior to implementation for guidance on customer passwords.
_________________________
Not even close to being legal advice....I have a bridge for sale too!

Return to Top
#211658 - 07/16/04 06:27 PM Re: 90-Day Password Changes
tomlokey Offline
New Poster
tomlokey
Joined: Jan 2003
Posts: 10
Florida
I'm not aware of any requirement for customers to change their passwords periodically. BofA does not have such a requirement.

Return to Top
#211659 - 07/16/04 06:55 PM Re: 90-Day Password Changes
Andy_Z Offline
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,750
On the Net
This is not unlike what I have heard in the past. The bank's internal systems require higher controls because there is more at risk.

If you ask a real IT type, they may want to apply the same rules. Often they don't like the username and password process from the very beginning. But where is it written or dictated that it has to be this way? Banks need to define the risks. And while I don't disagree with the regulator and IT types, better systems are more costly and if it is data entered by a user and not "one-time" limited use, it is potential phishing material and may be compromised easily any way. Better methods exist, but have much higher costs and require user acceptance.
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top
#211660 - 07/22/04 09:04 PM Re: 90-Day Password Changes
Queen Mum Offline
Power Poster
Queen Mum
Joined: Mar 2001
Posts: 3,920
OK
It was recommended to us in an IS exam that we have our IB set up for customers to require a password change every 90 days. Before that we did not but have sinced changed it to 90 days.

Return to Top
#211661 - 07/22/04 09:18 PM Re: 90-Day Password Changes
Andy_Z Offline
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,750
On the Net
And you made this change:
a) it seemed a better way (the bank and customers like it)
b) we felt that if it was "recommended" we should do it
c) they showed us a citation mandating the requirement
d) I'd rather not answer

Actually this is somewhat rhetorical unless they did show it to you in black and white in which case, please share.
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top

Moderator:  Andy_Z