DD ENV 12251:2001
Superseded
A superseded Standard is one, which is fully replaced by another Standard, which is a new edition of the same Standard.
View Superseded by
Health informatics. Secure user identification for health care. Management and security of authentication by passwords
Hardcopy , PDF
03-09-2004
English
19-10-2001
1 Scope
2 Normative references
3 Definitions
3.1 Access control
3.2 Authentication information
3.3 Authorised user
3.4 Default password
3.5 Identification
4 Requirements
4.1 Unique identification and authentication
4.2 Identification and authentication prior
to all other interactions
4.3 Associating unique identity with users
4.4 Maintaining the identity with users
4.5 Log-on message
4.6 Number of log-on trials
4.7 Incorrectly performed log-on procedure
4.8 Display of log-on statistics
4.9 Password sharing
4.10 Password storage
4.11 Logging of passwords
4.12 Passwords display suppression
4.13 User-changeability of passwords
4.14 Default passwords
4.15 Initialised passwords
4.16 Temporary passwords
4.17 Password expiration
4.18 Password expiration notification
4.19 Password reuse
4.20 Password complexity
Annex A (informative) Potential password complexity requirements
Annex B (informative) User responsibilities
Annex C (informative) Password communication
Annex D (informative) Bibliography
Designed to improve the authentication of individual users of health care IT system, by strengthening the automatic software procedures associated with the management of user identifiers and passwords, without resorting to additional hardware facilities.
Committee |
IST/35
|
DocumentType |
Standard
|
Pages |
20
|
PublisherName |
British Standards Institution
|
Status |
Superseded
|
SupersededBy |
Standards | Relationship |
ENV 12251 : DRAFT 2000 | Identical |
ISO 7498-2:1989 | Information processing systems Open Systems Interconnection Basic Reference Model Part 2: Security Architecture |
Access your standards online with a subscription
Features
-
Simple online access to standards, technical information and regulations.
-
Critical updates of standards and customisable alerts and notifications.
-
Multi-user online standards collection: secure, flexible and cost effective.