I'm not sure if this is the right place to post this. I apologize if it's not.
I'm the sole IT person at my company and am in charge of all systems, servers, software support, configurations, phones, etc.
There has never been a password policy in place. In fact, the box marked "change password at next logon" isn't checked when a new user account is added to the domain, so many passwords in the company are the original password given when they were first setup. Passwords are shared, rarely, if ever changed, easy to guess, etc, etc. This has bothered me since I arrived in this position a little more than a year ago but received resistance when I mentioned my concern so I haven't made any changes.
I've proposed a password policy that required users to change their passwords every 4 months, requires at least 8 characters and is med - strong. However, all of management is balking at it saying they don't want to change passwords, they need to be able to share them with other people in their department for access when they're out of the office, etc. So the owner of the company said No..we're not going to implement a password policy.
I'm going to meet with him today and ask him to reconsider. I'm willing to loosen the policy somewhat, but I'm very determined that a policy should be in place.
What's the best way to convince them of this?
Their mentality is to wait until there is a problem then act. I told them that if I wait until there is a problem, then I'm not doing my job.
If it helps, we're a manufacturing company with just under 100 employees, 45 of which have computer accounts.
I'm the sole IT person at my company and am in charge of all systems, servers, software support, configurations, phones, etc.
There has never been a password policy in place. In fact, the box marked "change password at next logon" isn't checked when a new user account is added to the domain, so many passwords in the company are the original password given when they were first setup. Passwords are shared, rarely, if ever changed, easy to guess, etc, etc. This has bothered me since I arrived in this position a little more than a year ago but received resistance when I mentioned my concern so I haven't made any changes.
I've proposed a password policy that required users to change their passwords every 4 months, requires at least 8 characters and is med - strong. However, all of management is balking at it saying they don't want to change passwords, they need to be able to share them with other people in their department for access when they're out of the office, etc. So the owner of the company said No..we're not going to implement a password policy.
I'm going to meet with him today and ask him to reconsider. I'm willing to loosen the policy somewhat, but I'm very determined that a policy should be in place.
What's the best way to convince them of this?
Their mentality is to wait until there is a problem then act. I told them that if I wait until there is a problem, then I'm not doing my job.
If it helps, we're a manufacturing company with just under 100 employees, 45 of which have computer accounts.