15
DOH IT STAFF ALL HANDS MEETING ENHANCED SECURITY ACCESS Department of Health 05/31/2017 1

All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

DOH IT STAFFALL HANDSMEETING

ENHANCED SECURITY ACCESS

Department of Health05/31/2017

1

Page 2: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Agenda Introduction  Current State Future State HIPAA Security Policy / Password Tips Summary Reset / Renew Password Register for Self Service Password Maintenance Self Service Password Reset / Forget Password Self Service Change Password Multi Factor Authentication Questions and Answers

Page 3: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Introduction

Objective Improve Security Access to DOH Resources

Office 365 (Email, OneDrive, SharePoint, etc.)Application Systems (EMR, Financial, Personnel)

Why? Active Directory:  Vulnerable to hackers DOH email Impossible Travel Security Alerts DOH email accounts appearing on Dark Web ETS Directive on Hardening Password Policy ETS Implementation of Multi‐factor Authentication

Page 4: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Current State

Current Security Access to Resources

Who Are You (Email Address)

What do you know (password) User choice – Length and Character String Permanent – Does not require changing

Too Vulnerable and not Secure Enough

Page 5: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Future State

Improve Security Access  Who Are You (Email Address) – No Change What do you know

Password  Amended Security Password Policy SP 03.11 Account locks  (for 15 minutes) after 5 invalid logon attempts

Security Questions – (3 out of 5)

What do you own (code –> text, email, voice) Smartphone / Desk Phone Email address

Page 6: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

HIPAA Security Policy Amending Security Policy ‐ SP 03.11  Change will include new parameters for password security: 10 characters minimum (lowercase/uppercase alphabet, numbers, and special characters).

Change every 90 days. 6 unique passwords before reusing a password.

Examples: DOH!sth3BE5t, Let5B3S@fe&

6

Page 7: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Password Tips DO

Use a passphrase to remember long passwords. Substitute letters with special characters (i.e., a to @). Protect your password like you would the keys to your house.

DON’T Use single dictionary words, sports teams, or popular names (such as Star Wars).

Use personal information. Use anything you would put on social media. Use a “one‐upped” password which means only changing your password by one character.

7

Page 8: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Summary ‐ Reset / Renew Password Register for Self Service Password Maintenance

http://aka.ms/ssprsetup

Self Service Password Reset / Forget Password http://portal.office.com Click on    Can’t access your account

Self Service Change Password http://portal.office.com Go to Settings  Click on    Change your password

Page 9: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Central Reference Web Site

http://password.doh.hawaii.gov From a Browser No log in Required

Web Site URL for Registration and Self‐Service Functions Detailed Step by Step instructions

Page 10: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Register Self Service Password Maintenance http://aka.ms/ssprsetup

Setup 2 of the 3 options: Office Phone

Extensions not supported

Authentication Phone Security Questions

Page 11: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Self Service Password Reset / Forget Password Self Service Password Reset / Forget Password

http://portal.office.com Click on    Can’t access your account Verify using options setup in registration (2 out of 3)

Office Phone Authentication Phone Security Questions

Reset your password

Page 12: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Self Service Change Password

Self Service Change Password http://portal.office.com Go to Settings  Click on    Change your password

OR

Domain computer – Ctrl + Alt + Delete 

Page 13: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Multi‐Factor Authentication (MFA)

User signs in from any device  Using existing username/password

Users must also authenticate using an email account, landline phone, mobile device, or authenticator app before access is granted Code is Requested by sign on process Code sent to Registered device or authenticator app (i.e. –Microsoft Authenticator or Google Authentiator) Text, email, Voice

Code entered in sign on process

Page 14: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Plan and Timetable May – Informational Briefings

DEC DOH IT Staff Distribution of Documentation to all DOH Staff

June  Staff Registration Period Training and Hands on Support System Configuration

July  Activate Enhanced Password Multi Factor Authentication Planning and Activation

Page 15: All Hands IT Staff Meeting 05312017.ppt - Hawaii Department of … · 2017. 6. 6. · Microsoft PowerPoint - All Hands IT Staff Meeting 05312017.ppt [Compatibility Mode] Author: christine.noguchi

Questions ??

15