Högskolan i Skövde

his.sePublikasjoner
Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
A current state analysis of password policies for Swedish municipalities
Högskolan i Skövde, Institutionen för informationsteknologi.
Högskolan i Skövde, Institutionen för informationsteknologi.
2024 (engelsk)Independent thesis Basic level (degree of Bachelor), 20 poäng / 30 hpOppgave
Abstract [en]

With cyber-attacks on the rise, secure authentication is an important commodity. With passwords being a prevalent authentication method, password creation policies need to be adapted to modern threats and social situations in order to assist users with upholding secure practices. This statement is as true in the public sector as it is in the private sector. This thesis aims to document the current state of password policies for municipalities in Sweden via the collection and analysis of password policies. The timing of this thesis is unfortunate, as the act of data collection, especially when it comes to a topic as sensitive as passwords, brings skepticism as a consequence of the current state of the world. Data collection requests were sent out to all 290 municipalities in Sweden, and 131 policy documents were ultimately obtained and analyzed. While the acquisition rate falls below the 166 that would have been needed for the scientific standard if data collection was from a random sample, it is believed that this amount still allows for a sufficiently detailed overview of the current landscape to be mapped out. The policies were subsequently anonymously coded using both an inductive and deductive approach. The analyzed data was used to measure the following: compliance with the policies compared to recommendations by five security agencies, how long a policy revision is used before a new revision is created and what changes between revisions, and whether a positive relation can be found between the creation date of a password policy and its specified minimum password length. The thesis found that 26% of the acquired policies currently in use were compliant with the recommendations by MSB, and 0.08% were compliant with ENISA. These rates might be a direct consequence of MSB having vague recommendations, and ENISA presenting what they deem is a strong password, not what they recommend as a minimum. Too few documents were acquired to make a general statement about policy age and changes between revisions. Furthermore, a significant positive relationship was found between password age and password length within the collected data.  

sted, utgiver, år, opplag, sider
2024. , s. 91
Emneord [en]
Passwords, password creation, password policy, cyber-security, public sector, municipalities, Sweden, password recommendations
HSV kategori
Identifikatorer
URN: urn:nbn:se:his:diva-24333OAI: oai:DiVA.org:his-24333DiVA, id: diva2:1883502
Fag / kurs
Informationsteknologi
Utdanningsprogram
Network and Systems Administration
Veileder
Examiner
Tilgjengelig fra: 2024-07-10 Laget: 2024-07-10 Sist oppdatert: 2024-07-10bibliografisk kontrollert

Open Access i DiVA

fulltext(1161 kB)128 nedlastinger
Filinformasjon
Fil FULLTEXT01.pdfFilstørrelse 1161 kBChecksum SHA-512
94dfbd3f868f6c4021a5deda81c48573cba2a1495113aec290dcf172b40808564fef1015fa3b4d89c53b8918b6040de4a7a6454b8071ed4cd63ac2cec355e12a
Type fulltextMimetype application/pdf

Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar
Totalt: 129 nedlastinger
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

urn-nbn

Altmetric

urn-nbn
Totalt: 488 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf