{"id":34455,"date":"2022-11-13T16:06:38","date_gmt":"2022-11-13T15:06:38","guid":{"rendered":"https:\/\/www.ebas.ch\/?page_id=34455"},"modified":"2024-08-30T09:25:53","modified_gmt":"2024-08-30T07:25:53","slug":"password-guidelines-for-sme","status":"publish","type":"page","link":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/","title":{"rendered":"Password guidelines for SME"},"content":{"rendered":"<div id=\"av_section_1\" class=\"avia-section av-3osj-8edf3c5c57d6f444e32a620ab19c7a5a main_color avia-section-default avia-no-border-styling  avia-builder-el-0  avia-builder-el-no-sibling  avia-bg-style-scroll container_wrap fullsize\"><div class=\"container av-section-cont-open\"><main role=\"main\" itemprop=\"mainContentOfPage\" class=\"template-page content  av-content-full alpha units\"><div class=\"post-entry post-entry-type-page post-entry-34455\"><div class=\"entry-content-wrapper clearfix\">\n\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-jo2xz-588590f8e0c3dd5b36ff4df9077018fa\">\n.flex_column.av-jo2xz-588590f8e0c3dd5b36ff4df9077018fa{\nborder-radius:0px 0px 0px 0px;\npadding:0px 0px 0px 0px;\n}\n<\/style>\n<div class=\"flex_column av-jo2xz-588590f8e0c3dd5b36ff4df9077018fa av_three_fourth  avia-builder-el-1  el_before_av_one_fourth  avia-builder-el-first  first flex_column_div av-zero-column-padding  \"><section class=\"av_textblock_section av-jvmci8ju-0d4bf5e1ee8402a49397872c2bc85092 \" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\"><div class=\"avia_textblock\" itemprop=\"text\"><p class=\"ebas-lead\">Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.<\/p>\n<div class=\"ebas-gist\">\n<h4>The most important points to remember:<\/h4>\n<ul>\n<li>Draw up a list of all <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span>-protected system and application access options in your organisation.<\/li>\n<li>Establish a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy for all system and application access options identified, stating your requirements for the creation, safekeeping and usage of all passwords.<\/li>\n<li>You should undertake periodic checks for strict adherence to your <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy.<\/li>\n<li>Sensitise all your employees to the dangers posed by improper <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> use.<\/li>\n<\/ul>\n<\/div>\n<h3>Why is a password policy necessary?<\/h3>\n<p>The combination of a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;User name&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is the name used by users to identify themselves in a system. When logging into a program or service (e. g. when e-banking), you will usually be asked for a user name and password. These will serve to identify authorised users.&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">user name<\/span> with a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> is still the most widely used method of <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Authentification&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is a process where the purported identity of a person or device is checked based on one or several specific characteristics (e. g. password, chip card or finger print).&lt;\/p&gt;\n&lt;p&gt;&amp;lt;img class=&amp;quot;size-full wp-image-25784 aligncenter&amp;quot; src=&amp;quot;https:\/\/www.ebas.ch\/wp-content\/uploads\/2020\/02\/authentisierung_en.png&amp;quot; alt=&amp;quot;&amp;quot; width=&amp;quot;212&amp;quot; height=&amp;quot;249&amp;quot; \/&amp;gt;&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">authentification<\/span> and <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Authorisation&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;The allocation of permissions. Based on permissions, authorisation is granted to access resources (e. g. files, software, payments, etc.) after successful identification and authentication.&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">authorisation<\/span> in any digital operating environment. For instance, this serves to confirm a user&rsquo;s identity and to implement access protection when accessing networks, logging into computer systems or using third-party services and applications. User names and passwords therefore play a central role in cyber security.<\/p>\n<p>It is not surprising then that cyber-criminals do their utmost to obtain this much sought-after information by means of hacking, <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> or <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Social engineering&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is an attack which does not really take place by technical, but by psychological means. It is a wide-spread method of snooping on confidential information. This always targets humans. To obtain such confidential information, it is not only people&rsquo;s credulity and helpfulness which are being exploited, but also their insecurities. Anything from faked telephone calls to people pretending to be someone else and phishing attacks is possible.&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">social engineering<\/span> and to then take on the digital identity of their victim this way.<\/p>\n<p>Users however are so familiar with the use of passwords that they quite frequently are not sufficiently aware of the risks involved. In an organisational environment in particular, a clear <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy providing users with clear instructions and protecting them from errors in this regard is therefore vital.<\/p>\n<h3>What is a password policy, and how do you create an effective one?<\/h3>\n<p>A <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy is defined as a set of rules drawn up to increase cyber security by encouraging employees to create secure passwords, to store them safely and to use them properly. A <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy is part of the official rules of an organization and should be part of any security awareness training programs.<\/p>\n<p>It should be customized in accordance with the needs (of the complete system environment) and requirements (on a security level) of any organization so to ensure you achieve optimum effectiveness with reasonable effort. A first step should therefore consist of drawing up a list of all <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span>-protected systems and application access options in an organisation and to assess the protection levels required. All access options thus identified will then have to be considered when drawing up suitable rules inside a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy.<\/p>\n<p>To be able to cope with the ever-changing threat situation, the <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy should be subject to periodical checks for continued relevance and effectiveness.<\/p>\n<h3>Which are the most important aspects of a password policy?<\/h3>\n<p>A <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy extensively regulates how passwords are handled inside an organization. It provides users with specific instructions and covers the following:<\/p>\n<h4>1. Use of passwords<\/h4>\n<p>As mentioned above, it is often already sufficient to know a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> to completely take on someone&rsquo;s digital identity. You should generally therefore take all measures necessary to prevent any fraudulent use of this information.<\/p>\n<p>Passwords are therefore strictly private and must be treated confidentially. Below some points to be particularly aware of:<\/p>\n<ol>\n<li>Passwords must neither be passed on actively nor shared nor stored in a place open to the public.<\/li>\n<li>Passwords must always be stored and transmitted in encrypted form.<\/li>\n<li>When entering passwords, make sure that this process cannot be overlooked by third parties.<\/li>\n<\/ol>\n<p>A <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy establishes guidelines on the use of passwords by way of a directive.<\/p>\n<h4>2. Password strength<\/h4>\n<p>The strength of a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> is a measure of how difficult it will be for an attacker to discover a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> unknown to them by simple guesswork or trial and error. The more unpredictable and complex and the longer a chosen <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> is, the stronger and hence more secure it is.<\/p>\n<p>A good <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy emphasizes the creation of strong passwords by requiring users to make their passwords longer and less predictable (see our instructions on <a href=\"https:\/\/www.ebas.ch\/it\/4-proteggere-gli-accessi-online\/#passwords\">&ldquo;Secure passwords&rdquo;<\/a>).<\/p>\n<p>In addition, the creation of strong passwords should be supported by providing technical tools, such as <a href=\"https:\/\/www.ebas.ch\/it\/4-proteggere-gli-accessi-online\/#passwords\">password managers<\/a> and stipulated in the <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy.<\/p>\n<h4>3. Password expiry<\/h4>\n<p>It is very simple to transfer passwords &ndash; something which over time can also result in them ending up in the wrong hands. Employees for instance sometimes pass on passwords to third parties without thinking or note them down in unprotected places. User passwords can also be disclosed unintentionally though as a result of data breaches. It is generally impossible to reclaim any leaked data.<\/p>\n<p>In any such cases, changing passwords is the only effective measure to restore cyber security since this will render any leaked information useless.<\/p>\n<p>The renewal and administration of passwords should be arranged for with the help of technical tools, such as making support from a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> manager utility available.<\/p>\n<h4>4. Password history<\/h4>\n<p>Users tend to reduce the number of passwords they have to remember, for instance by reusing passwords they have used in the past. Cyber criminals <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Exploit&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;An &amp;lt;strong&amp;gt;exploit&amp;lt;\/strong&amp;gt; is a term denominating malicious software which specifically exploits a certain vulnerability to compromise a system.&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>exploit<\/span> that kind of behaviour by regularly using lists with old passwords when carrying out their attacks. To make this impossible, users should be prevented from reactivating old passwords.<\/p>\n<p>A <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy will ensure that systems keep track of a user&rsquo;s <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> history and check for reuse of old passwords when these are changed.<\/p>\n<h4>5. Password changes<\/h4>\n<p>Users should be able to change their passwords at any time and by themselves. However, you will need to ensure that such <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> changes are exclusively initiated by legitimate owners and not by attackers.<\/p>\n<p>A <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy establishes the technical and organisational framework conditions providing for secure <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> changes. The introduction of two factor <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Authentification&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is a process where the purported identity of a person or device is checked based on one or several specific characteristics (e. g. password, chip card or finger print).&lt;\/p&gt;\n&lt;p&gt;&amp;lt;img class=&amp;quot;size-full wp-image-25784 aligncenter&amp;quot; src=&amp;quot;https:\/\/www.ebas.ch\/wp-content\/uploads\/2020\/02\/authentisierung_en.png&amp;quot; alt=&amp;quot;&amp;quot; width=&amp;quot;212&amp;quot; height=&amp;quot;249&amp;quot; \/&amp;gt;&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">authentification<\/span> for instance can render the process of changing passwords considerably more secure.<\/p>\n<\/div><\/section><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-e2kbb-86d4495b00c389f290046e9e5f6e0589\">\n.flex_column.av-e2kbb-86d4495b00c389f290046e9e5f6e0589{\nborder-radius:0px 0px 0px 0px;\npadding:0px 0px 0px 0px;\n}\n<\/style>\n<div class=\"flex_column av-e2kbb-86d4495b00c389f290046e9e5f6e0589 av_one_fourth  avia-builder-el-3  el_after_av_three_fourth  avia-builder-el-last  ebas-sidebar flex_column_div av-zero-column-padding  \"><section class=\"av_textblock_section av-jvmf7hs6-cdd0349598971eb47506440bac4ee296 \" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\"><div class=\"avia_textblock\" itemprop=\"text\"><p>Passwords are still the most widely used security component of access protection in a digital environment. It is not surprising then that cyber-criminals do their utmost to obtain this much sought-after information by means of hacking, <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> or <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Social engineering&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is an attack which does not really take place by technical, but by psychological means. It is a wide-spread method of snooping on confidential information. This always targets humans. To obtain such confidential information, it is not only people&rsquo;s credulity and helpfulness which are being exploited, but also their insecurities. Anything from faked telephone calls to people pretending to be someone else and phishing attacks is possible.&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">social engineering<\/span>.<\/p>\n<p><span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">Password<\/span> guidelines (or a &ldquo;<span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> policy&rdquo;) ensure clarity and certainty when handling passwords!<\/p>\n<\/div><\/section><\/div>\n<\/div><\/div><\/main><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.<\/p>\n","protected":false},"author":1,"featured_media":34447,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[496],"tags":[],"class_list":["post-34455","page","type-page","status-publish","has-post-thumbnail","hentry","category-tips-for-smes"],"acf":[],"yoast_head":"<title>Password guidelines for SME - \u00abeBanking \u2013 but secure!\u00bb<\/title>\n<meta name=\"description\" content=\"Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Password guidelines for SME - \u00abeBanking \u2013 but secure!\u00bb\" \/>\n<meta property=\"og:description\" content=\"Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/\" \/>\n<meta property=\"og:site_name\" content=\"\u00abeBanking \u2013 but secure!\u00bb\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-30T07:25:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ebas.ch\/wp-content\/uploads\/2022\/11\/KMUPasswortPolicy-1030x687.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1030\" \/>\n\t<meta property=\"og:image:height\" content=\"687\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/\",\"name\":\"Password guidelines for SME - \u00abeBanking \u2013 but secure!\u00bb\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/KMUPasswortPolicy-scaled.jpg\",\"datePublished\":\"2022-11-13T15:06:38+00:00\",\"dateModified\":\"2024-08-30T07:25:53+00:00\",\"description\":\"Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/KMUPasswortPolicy-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/KMUPasswortPolicy-scaled.jpg\",\"width\":2048,\"height\":1365,\"caption\":\"New strong password and weak ones near keyboard.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/password-guidelines-for-sme\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tips for SMEs\",\"item\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/category\\\/tips-for-smes\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Password guidelines for SME\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/\",\"name\":\"\u00abeBanking \u2013 but secure!\u00bb\",\"description\":\"\u00abeBanking \u2013 but secure!\u00bb is an independent platform meant to help you maintain your personal computer security.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#organization\",\"name\":\"\u00abeBanking \u2013 aber sicher!\u00bb\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/logo_ebas_de.svg\",\"contentUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/logo_ebas_de.svg\",\"width\":10,\"height\":1,\"caption\":\"\u00abeBanking \u2013 aber sicher!\u00bb\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>","yoast_head_json":{"title":"Password guidelines for SME - \u00abeBanking \u2013 but secure!\u00bb","description":"Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/","og_locale":"en_US","og_type":"article","og_title":"Password guidelines for SME - \u00abeBanking \u2013 but secure!\u00bb","og_description":"Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.","og_url":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/","og_site_name":"\u00abeBanking \u2013 but secure!\u00bb","article_modified_time":"2024-08-30T07:25:53+00:00","og_image":[{"width":1030,"height":687,"url":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2022\/11\/KMUPasswortPolicy-1030x687.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/","url":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/","name":"Password guidelines for SME - \u00abeBanking \u2013 but secure!\u00bb","isPartOf":{"@id":"https:\/\/www.ebas.ch\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/#primaryimage"},"image":{"@id":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2022\/11\/KMUPasswortPolicy-scaled.jpg","datePublished":"2022-11-13T15:06:38+00:00","dateModified":"2024-08-30T07:25:53+00:00","description":"Computer system and network security are crucially dependent on handling passwords correctly. The implementation of password guidelines or a password policy regulates creation, safekeeping and usage of passwords in an organisation.","breadcrumb":{"@id":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/#primaryimage","url":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2022\/11\/KMUPasswortPolicy-scaled.jpg","contentUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2022\/11\/KMUPasswortPolicy-scaled.jpg","width":2048,"height":1365,"caption":"New strong password and weak ones near keyboard."},{"@type":"BreadcrumbList","@id":"https:\/\/www.ebas.ch\/en\/password-guidelines-for-sme\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ebas.ch\/en\/"},{"@type":"ListItem","position":2,"name":"Tips for SMEs","item":"https:\/\/www.ebas.ch\/en\/category\/tips-for-smes\/"},{"@type":"ListItem","position":3,"name":"Password guidelines for SME"}]},{"@type":"WebSite","@id":"https:\/\/www.ebas.ch\/en\/#website","url":"https:\/\/www.ebas.ch\/en\/","name":"\u00abeBanking \u2013 but secure!\u00bb","description":"\u00abeBanking \u2013 but secure!\u00bb is an independent platform meant to help you maintain your personal computer security.","publisher":{"@id":"https:\/\/www.ebas.ch\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ebas.ch\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.ebas.ch\/en\/#organization","name":"\u00abeBanking \u2013 aber sicher!\u00bb","url":"https:\/\/www.ebas.ch\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ebas.ch\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2020\/06\/logo_ebas_de.svg","contentUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2020\/06\/logo_ebas_de.svg","width":10,"height":1,"caption":"\u00abeBanking \u2013 aber sicher!\u00bb"},"image":{"@id":"https:\/\/www.ebas.ch\/en\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/pages\/34455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/comments?post=34455"}],"version-history":[{"count":3,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/pages\/34455\/revisions"}],"predecessor-version":[{"id":41618,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/pages\/34455\/revisions\/41618"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/media\/34447"}],"wp:attachment":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/media?parent=34455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/categories?post=34455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/tags?post=34455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}