Why is Yale adopting a regular password change requirement?
Activities at Yale increasingly involve electronic systems, including online courses, grades, financial aid, many Yale business systems, faculty and staff benefits, IRS reporting, and more. As custodians for IT security at Yale, ITS strives to pursue every prudent step to maintain the security and integrity of your own and Yale’s electronic systems. One critical layer of IT security is your personal password. This is not only a key to the security of your own account but to the security of the Yale community because most system-wide attacks begin with the compromise of an individual account. Like running virus protection, periodic password changes are basic security hygiene. It can be disruptive to change passwords on a forced schedule, so, in the past, Yale has recommended a regular change and relied on individuals to do so voluntarily. A recent review of security risks highlighted the importance of password protection, and a review of password change statistics showed that few users