Högskolan i Skövde

his.sePublications
System disruptions
We are currently experiencing disruptions on the search portals due to high traffic. We are working to resolve the issue, you may temporarily encounter an error message.
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A current state analysis of password policies for Swedish municipalities
University of Skövde, School of Informatics.
University of Skövde, School of Informatics.
2024 (English)Independent thesis Basic level (degree of Bachelor), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

With cyber-attacks on the rise, secure authentication is an important commodity. With passwords being a prevalent authentication method, password creation policies need to be adapted to modern threats and social situations in order to assist users with upholding secure practices. This statement is as true in the public sector as it is in the private sector. This thesis aims to document the current state of password policies for municipalities in Sweden via the collection and analysis of password policies. The timing of this thesis is unfortunate, as the act of data collection, especially when it comes to a topic as sensitive as passwords, brings skepticism as a consequence of the current state of the world. Data collection requests were sent out to all 290 municipalities in Sweden, and 131 policy documents were ultimately obtained and analyzed. While the acquisition rate falls below the 166 that would have been needed for the scientific standard if data collection was from a random sample, it is believed that this amount still allows for a sufficiently detailed overview of the current landscape to be mapped out. The policies were subsequently anonymously coded using both an inductive and deductive approach. The analyzed data was used to measure the following: compliance with the policies compared to recommendations by five security agencies, how long a policy revision is used before a new revision is created and what changes between revisions, and whether a positive relation can be found between the creation date of a password policy and its specified minimum password length. The thesis found that 26% of the acquired policies currently in use were compliant with the recommendations by MSB, and 0.08% were compliant with ENISA. These rates might be a direct consequence of MSB having vague recommendations, and ENISA presenting what they deem is a strong password, not what they recommend as a minimum. Too few documents were acquired to make a general statement about policy age and changes between revisions. Furthermore, a significant positive relationship was found between password age and password length within the collected data.  

Place, publisher, year, edition, pages
2024. , p. 91
Keywords [en]
Passwords, password creation, password policy, cyber-security, public sector, municipalities, Sweden, password recommendations
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-24333OAI: oai:DiVA.org:his-24333DiVA, id: diva2:1883502
Subject / course
Informationsteknologi
Educational program
Network and Systems Administration
Supervisors
Examiners
Available from: 2024-07-10 Created: 2024-07-10 Last updated: 2024-07-10Bibliographically approved

Open Access in DiVA

fulltext(1161 kB)118 downloads
File information
File name FULLTEXT01.pdfFile size 1161 kBChecksum SHA-512
94dfbd3f868f6c4021a5deda81c48573cba2a1495113aec290dcf172b40808564fef1015fa3b4d89c53b8918b6040de4a7a6454b8071ed4cd63ac2cec355e12a
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 119 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 442 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf