Do

  • Do enable MFA (Okta) where possible.
  • Do use a purpose-built password manager for passwords or secrets. The State provides a password manager for all staff supported by the Office of Administration. If you need access to the password manager, please submit a help desk ticket.
  • Do use randomly generated, lengthy passwords for those you don’t need to memorize or don’t use often and store them in a password manager.

    Example: 98vgjJ7%PdX$zgtUziE#7ahpAa2jE4V is a very secure password and is easy to copy and paste into a password field.
  • Do use Passphrases. A passphrase is a security method utilizing a long sequence of random words instead of a single short word or a complex string of symbols. By prioritizing length over character variety, it becomes significantly harder for computer programs to crack while remaining much easier for a person to memorize.
  • Do use long passwords/passphrases; 15 characters or longer.
  • Do use Passphrases that contain 5 or more unrelated words, including words with uppercase and a special character.

    Examples: Chocolate.BadPizzaPieBurger, Pirate.EatsLemonUnderMoon
  • Do mix characters case, special characters and numbers into a Passphrase.

    Example: Tulip-River-Orange-Satellite-Bacon7, Tiger-banana38-tree-Puppy-Beef, CatsOnSkateboardsLovePizza#6
  • Do add spaces, if the system allows it.

    Example “good lava chick3n is Cold”
  • Do be vigilant for phishing and scam sites that might look like official sites but are just trying to steal your credentials.

Do Not

  • Do not use Passphrases that are valid sentences or proper grammar.
  • Do not use the same password on multiple accounts, including work and personal accounts.
  • Do not store passwords in clear text, written down on paper, in a digital application such as Notepad or a notes application on your phone. Also, do not store passwords in “encrypted” documents. Only store passwords in authorized password manager applications.
  • Do not put passwords into any ticketing system. Ticketing systems are not designed to protect sensitive information.
  • Do not increment passwords. This is comparable to password reuse.
    Examples: Password1, then Password2, then Password3
  • Do not use months, years or seasons as these are a common target for hackers.
    Examples: Summer25, November2025, Password2025
  • Do not use ‘hacker speak’ alone with a single word password to make the password complex.
    Examples: ‘P@ssword’, ‘P@ssw0rd’, ‘blu3j@y’. It is acceptable to use “hacker speak” on passphrases with 3 or more words.
  • Do not use simple repetitive keyboard patterns:
    Examples: ‘qwerty’, ‘123456’, ‘zxcvbnm’or ‘asdfghjkl’.
  • Do not use passwords that have a pattern across vendors platforms.
    Examples: Xgoogle1!, Xfacebook1!, Xmicrosoft1!, Xapple1!
  • Do not use proper sentences or passphrases that ‘make complete sense’ or are commonly known.
    Examples: “I love my dog!”, “The quick brown fox jumps over the lazy dog”, “Every Good Boy Does Fine”
  • Do not use simple dictionary words with a number at the end.
    Examples: “Birthday1”, “Flamingo2”
  • Do not use data that is personal or related to a favorite item on social media! Avoid names, birthdays, pet’s names, addresses, sports teams, cities, employers, etc.
    Example, Sparky#1, Chief#1, CardinalsRock#1, MyDogIsNamedSparky
  • Do not give your password/passphrase to anyone, even if they are or claim to be ‘technical support’. ITSD or other support staff should never ask for your password.
  • Do not use passphrases that are just one word or a few words repeated.
    Examples: PeachesPeachesPeachesPeachesPeaches, BlueSkyBlueSkyBlueSky
  • If a system requires the use of security questions and answers, do not use valid. Store the question and answer in a password manager.
    Example of how to correctly answer: Question – “What was your first pets name?” Answer – “nuclear submarine”