MVS Accounts and Passwords
Objectives, recomendations, rules and regulations
The objective for system security is to protect critical business information and allow access to those individuals who are authorized to access that information.
Failure to do so can lead to:
- unauthorized possession of critical data
- damage to critical business information
- privacy issue improprieties
- litigation
- lost revenue
- operational disruption
The solution is to
restrict computer processing activities to only those people who have the
proper authority and to limit their activity to those functions that fall
within their assigned duties.
Our recommendations to all users:
- do not write down your logon id or password
- do not share your logon ID and passwords with others
- pay special attention to the "LAST USED MESSAGE"
- report any suspected unauthorized access to the Computer Center
- use the TSS LOCK and UNLOCK commands (see below)
Our recommendations to Managers and Supervisors:
- do not allow employees to share logon IDs
- notify Computing Services when an employee is terminated or transfers so that their logon ID can be deleted.
Listed below are some basic Rules and Regulations to follows:
- all users must have a unique access id (ACID) and password
- each user must change their password at least once every 60 days. Passwords may be changed as often as necessary.
- all security violations, whether intentional or unintentional, will be logged when they occur. Security violation reports will be prepared and distributed to the appropriate individual.
- TSS will warn you fourteen (14) days prior to the expiration of your password.
- ACID Termination - when an employee transfers from one department to another or terminates, the employee's supervisor should call Computing Services' Help Desk at x6420 and request that the ACID be terminated.
- all new employees will be assigned a new ACID.
- the maximum number of password violations is three.
- the maximum number of violations is five.
General Password Rules:
- passwords must be a minimum of 5 alpha-numeric characters and not more than 8 alpha-numeric characters in length.
- passwords in the restricted list are not allowed.
- passwords which match the userid or first four characters of any word in the associated name field are not allowed.
- new passwords cannot be the same as any of the two previous passwords.
- no repetition of successive characters are allowed.
TSS LOCK / UNLOCK command:
- TSS LOCK will lock your terminal and results in immediate termination of the request before it executes.
- TSS UNLOCK will prompt the user for their password and then unlock the terminal.
- Last Used Message - TSS will provide information about the last time the ACID was used.
If you have any questions concerning your account, contact your manager or supervisor or call the help Desk at x6420.
To Return to the ACS Home Page
Last Revised 10/01/2003