cougie uk
Guru
Some years ago I was talking to a IT person at an IT conference - he was an expert on IT security
One of the site he audited annually was a VERY secure site - MOD or similar - he could look at the policies, minutes of meetings and all that
but he was NOT allowed to enter the building where the VDUs (it was a long time ago) were used - so his audit was always conditional - polices were great but he had no evidence they were applied on the floor
basically every user had a password that was changed every Monday - and could not be a real word and had to be about 10 characters long
and all that
After a few years of people complaining about this they let him on site after signing a load of forms
He went first thing on a Monday - deliberatly
Every desk had a piece of card on it and a pen and a blob of blu Tack
every VDU had a piece of card with the current password
and the blank piece was for this week's password
totally made the policy redundant - but it was the only way they could operate a large VDU floor with low paid data entry staff
My point is - a policy is useless is people can;t keep to it - or if it makes life difficult for them because humans are clever, intelligent and devious - and sooner or later someone will find a way to sidestep it and make it easier
Amateurs. Surely you should hide it under the mouse mat.