Password Security

The University has implemented the following requirements for SMU passwords:

  • Passwords must be a minimum of 8 characters in length.
  • Passwords may not contain all or part of the user’s account name.
  • Passwords must contain characters from at least 3 of the following 4 categories:
    • English uppercase letters (A, B, C… Z)
    • English lowercase letters (a, b, c… z)
    • Base-10 digits (0, 1, 2… 9)
    • Non-alphanumeric characters (for example; !, $, #, %)

Password Accounts

  • Passwords must be set to expire after six months.
  • Accounts must be set to become locked after 10 invalid login attempts.

Password Tips and Usage

  • Passwords should not be shared with anyone, including supervisors, co-workers, and ITS Staff members.
  • No one should ask you for your password.
  • Passwords should be easy to remember, but difficult to guess
  • Passwords should not be written down
  • Passwords should not be sent via email, instant message, or cellular phone “text message”
  • Passwords should not be stored in a file on your computer
  • Passwords should not be reused
  • Passwords should not contain words that can be found in a dictionary, or foreign words
  • Passwords should not contain personal information, including birth dates, anniversary dates, license plates, phone numbers, addresses, family member names, pet names, etc
  • Passwords should not contain simple transformations of words (7eleven, seven11, etc)
  • Passwords should not contain sequential alphabet or keyboard information (abcdef, 654321, qwerty, etc)
  • One way to select a good password is to create an easy to remember sentence, such as “I ride the train to work every day.” Then, take the first letter of each word in the sentence, and mix in upper- and lowercase letters, numbers, and/or symbols. In this example, you might end up with a password of “iRttTweD!” or “IRTt2Wed”.
  • If your browser automatically remembers usernames and passwords, it is a good idea to disable this feature. Open Internet Explorer and click on Tools -> Internet Options. Select the “Content” tab, and click the “Auto Complete” button. You will then be able to clear all passwords from your browser and uncheck the option to save usernames and passwords.