Högskolan i Skövde

his.sePublikationer
Ändra sökning
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
A current state analysis of password policies for Swedish municipalities
Högskolan i Skövde, Institutionen för informationsteknologi.
Högskolan i Skövde, Institutionen för informationsteknologi.
2024 (Engelska)Självständigt arbete på grundnivå (kandidatexamen), 20 poäng / 30 hpStudentuppsats (Examensarbete)
Abstract [en]

With cyber-attacks on the rise, secure authentication is an important commodity. With passwords being a prevalent authentication method, password creation policies need to be adapted to modern threats and social situations in order to assist users with upholding secure practices. This statement is as true in the public sector as it is in the private sector. This thesis aims to document the current state of password policies for municipalities in Sweden via the collection and analysis of password policies. The timing of this thesis is unfortunate, as the act of data collection, especially when it comes to a topic as sensitive as passwords, brings skepticism as a consequence of the current state of the world. Data collection requests were sent out to all 290 municipalities in Sweden, and 131 policy documents were ultimately obtained and analyzed. While the acquisition rate falls below the 166 that would have been needed for the scientific standard if data collection was from a random sample, it is believed that this amount still allows for a sufficiently detailed overview of the current landscape to be mapped out. The policies were subsequently anonymously coded using both an inductive and deductive approach. The analyzed data was used to measure the following: compliance with the policies compared to recommendations by five security agencies, how long a policy revision is used before a new revision is created and what changes between revisions, and whether a positive relation can be found between the creation date of a password policy and its specified minimum password length. The thesis found that 26% of the acquired policies currently in use were compliant with the recommendations by MSB, and 0.08% were compliant with ENISA. These rates might be a direct consequence of MSB having vague recommendations, and ENISA presenting what they deem is a strong password, not what they recommend as a minimum. Too few documents were acquired to make a general statement about policy age and changes between revisions. Furthermore, a significant positive relationship was found between password age and password length within the collected data.  

Ort, förlag, år, upplaga, sidor
2024. , s. 91
Nyckelord [en]
Passwords, password creation, password policy, cyber-security, public sector, municipalities, Sweden, password recommendations
Nationell ämneskategori
Systemvetenskap, informationssystem och informatik med samhällsvetenskaplig inriktning
Identifikatorer
URN: urn:nbn:se:his:diva-24333OAI: oai:DiVA.org:his-24333DiVA, id: diva2:1883502
Ämne / kurs
Informationsteknologi
Utbildningsprogram
Nätverks- och systemadministration, 180 hp
Handledare
Examinatorer
Tillgänglig från: 2024-07-10 Skapad: 2024-07-10 Senast uppdaterad: 2024-07-10Bibliografiskt granskad

Open Access i DiVA

fulltext(1161 kB)125 nedladdningar
Filinformation
Filnamn FULLTEXT01.pdfFilstorlek 1161 kBChecksumma SHA-512
94dfbd3f868f6c4021a5deda81c48573cba2a1495113aec290dcf172b40808564fef1015fa3b4d89c53b8918b6040de4a7a6454b8071ed4cd63ac2cec355e12a
Typ fulltextMimetyp application/pdf

Av organisationen
Institutionen för informationsteknologi
Systemvetenskap, informationssystem och informatik med samhällsvetenskaplig inriktning

Sök vidare utanför DiVA

GoogleGoogle Scholar
Totalt: 126 nedladdningar
Antalet nedladdningar är summan av nedladdningar för alla fulltexter. Det kan inkludera t.ex tidigare versioner som nu inte längre är tillgängliga.

urn-nbn

Altmetricpoäng

urn-nbn
Totalt: 468 träffar
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf