Skip to main content Skip to navigation
Information Technology Services

Information Security Services

Welcome

As part of WSU’s Information Technology Services, our Information Security Services (ISS) group works around the clock to protect the data resources of students, faculty and staff, as well as protecting the confidentiality, integrity, and availability of information important to the university’s mission.

ISS is responsible for managing security risks to information technology assets at the University. The strategic objectives include: data loss prevention, the improved security of system and network services, proactive risk management, and crisis and security incident management.

Find information on topics such as Incident Reporting Procedures, Policies and Guidelines, and Security FAQ’s

 

How to change your password

Password Assistance

WSU Password Policy

As described in the existing WSU Executive Policy 18, passwords will be required to be reset every 180 days, starting at the date of your most recent password change.

Reminder

Once you have reset your password, you will need to update your account information for wireless internet access and applications on your mobile devices.

Failure to do so may result in your account being locked out due to multiple failed attempts to connect with your account.

Change or Recover Network ID

To change your WSU Network ID, Friend ID or Password

Please go to https://reset.wsu.edu and log in to begin changing your password.

  • As an added security precaution, faculty and staff will be asked two security questions before being allowed to change their password: start date at WSU and the approximate gross amount of their last paycheck.
  • Once you have started the process, you will have 15 minutes to complete your password reset, then the session will time out.

To Recover your WSU Network ID or Friend ID

  • Call CougTech at 509-335-4357

Tri-Cities Account

To change the password for your Tri-Cities account

Please go to https://tricities.wsu.edu/ctc/change-wsutc-network-password/ and fill out the form.

You can also reset your local WSUTC account via the following method:

  • Log in to your workstation
  • After it has booted up, press Ctrl/Alt/Delete and click on “Change a Password.”
  • Follow the instructions on the screen.

VetMed Account

To change the password for your VetMed account (username@vetmed.wsu.edu)

Please contact the VetMed IT help desk.

Password Requirements

Minimum Characters8
Letter - Number - Special Characters (i.e., !, @, #, $, ?)At least 1 of each
Case SensitiveYes
Character Change Requirement for PW Resets3 characters must change
Password Expiration180 Days
Inactivity Deactivation Threshold90 Days
Lockout Policy5 Consecutive Failures
Lockout Duration5 minutes

Tips & Tricks

How to create a strong password that you can remember

Avoid names, places, family, pets, and dictionary words.

KardashianFan, Cancun, George, Fido, and any word you could look up in a dictionary are right out. They’re too easy for people to guess, and hackers can build programs that automatically try known words.

Instead, use abbreviated phrases and multiple words or fragments of words. Substitute numbers and special characters for letters or entire words to break up patterns—make it easy to remember, but impossible for anyone else to guess.

Connect the first letters of a passphrase:

  • 1ibLn+Tib5e = One if by land, two if by sea

Take a sentence and turn it into a password:

  • WOO!TSwontSB = Woohoo! The Seahawks won the Super Bowl!
  • PPupmoarT@O@tgs = Please pick up more Toasty O’s at the grocery store.
  • W?ow?imp::ohth3r = Where oh where is my pear? Oh, there.

Nursery rhyme:

  • HD504w,HDh4gf = Humpty Dumpty sat on a wall, Humpty Dumpty had a great fall.

Favorite line of a song or movie:

  • yMw4h4yF50e!! = Your mother was a hamster and your father smelled of elderberries!

Use a Keyboard Pattern:
keyboard

  • #WAxcvgy7890-

Consider doubling an easier password:

  • B04t5xB04t5! = Boats x Boats

Reverse any of the above.

Phishing

Phishing is an attempt to trick you into revealing private information. Emails, texts, or phone calls can “fish” for information by trying to lure you into clicking on a malicious link or attachment, or giving passwords, credit card numbers, etc., to a malicious third party. Report suspicious emails and phishing scams to  abuse@wsu.edu

HOW TO RECOGNIZE A PHISHING ATTEMPT

  • Legitimate companies do not ask for personal info via email or text.
  • Messages may appear to be from organizations you do business with.
  • Sense of urgency: Messages may include threatening statements to close an account if you fail to respond, often indicating that such threats will be executed “immediately.”
  • Obvious grammatical errors, spelling errors, and strange word choices. Messages from legitimate companies are usually written by professional communicators who won’t make such errors.

Key:

  1. Sender’s email address: Official WSU communications will always be sent from a wsu.edu address. However be cautious, just because it does come from a wsu.edu address does not guarantee that it is legit either.
  2. Impersonal or awkward greeting: Most phishing emails do NOT refer to the recipient by name.
  3. Spelling: Official emails should not have spelling or grammatical mistakes.
  4. Ultimatum: Urgent warning attempts to scare you into responding quickly and without thought.
  5. WSU will never ask for your password or other personal information via email.
  6. Bogus URL: Official WSU websites will always end in wsu.edu. Website URLs are easily obscured. DO NOT click. Instead, hover over the link to verify destination URL.
  7. Security disclaimer: This does not mean the message is genuine.
  8. No signature or contact info: Official WSU business will always include WSU phone, email, and web address.

HOW TO SPOT:

Sample phishing email:

 

 

WHAT TO DO IF YOU SUSPECT YOU’RE BEING PHISHED:

  • If you think the message might be legitimate, or if you’re worried about the consequences of ignoring it, look up the organization independently and contact them directly.
  • Do not click on links or call phone numbers provided in the message. They may redirect you to fake sites that mimic the real thing.
  • Do not open attachments that are unexpected or from unverified sources.
  • Do not send your password via email.
  • Only sign in if you are 100% sure you are on the real site.
  • Report suspicious emails and phishing scams to abuse@wsu.edu.

Malware

Any unprotected computer connected to the internet is likely to be infected within minutes. Malware infections put your personal data—and everyone you’re connected to—at risk.

PROTECT YOURSELF AGAINST MALWARE

  • Keep your system up to date
  • Use anti-virus software
  • Do not install untrusted software

 

MALWARE SYMPTOMS:

  • Change of browser homepage/start page
  • Changed settings which cannot be changed back
  • Ending up at a strange site when using search
  • System firewall has been turned off
  • Increased network activity while not active
  • Excessive pop-up windows
  • New icons, programs, or favorites which you did not add
  • Frequent firewall alerts about unknown programs
  • Bad/slow system performance

 

Policies, Standards and Guidelines

Security Guidelines

WSU’s Information Security Program (ISP) is managed and operated by the central Information Technology Services Department (ITS) of WSU. Within ITS the Information Security Program has a broad role and responsibility with respect to information security and privacy across the Institution. The mission of WSU’s ISP is to provide clear and flexible information security and privacy policies, procedures, standards, and risk mitigations to enable Washington State University to safely carry out its mission and accomplish its strategic goals.

The Program exists to appropriately protect, maintain, and ensure legal, compliant, and appropriate use of the university’s information technology assets. Security and privacy policies work together to lay the foundation for the campus community to build and operate a high quality and trusted campus computing environment.

This web page it is not an exhaustive list. Laws, policies, and regulations not specific to information technology may also apply, e.g.: student conduct, personnel policy or contract, sexual harassment, chain letter laws, etc.

Policies

The information provided here is intended to complement the requirements outlined in WSU Business Policies and Procedures Manuals (BPPM) and WSU Executive Policy Manuals (EP).

Standards (Proposed)

Guidelines

Identity Theft Prevention

 

WSU ITS RSS Feed

Chinese Government Hackers Reportedly Stole Trove of Sensitive U.S. Naval Data:
A new report claims that Chinese government hackers stole more than 614 gigabytes of sensitive data from a U.S. Navy contractor. The attacks occurred in January and February and were conducted by a division of the Chinese Ministry of State Security. The target was a contractor that works for the Naval Undersea Warfare Center and conducts research and development for submarines and underwater weapons systems. The stolen data is said to include secret plans to develop a new submarine-launched anti-ship missile as well as information about sensors and submarine cryptographic systems. Chinese hackers have frequently targeted U.S. military contractors and have previously succeeded in stealing information about the new F-35 stealth fighter, the advanced Patriot PAC-3 missile system, and other sensitive projects.

Entire Article: https://www.theguardian.com/world/2018/jun/08/chinese-hackers-us-navy-submarine-missile-secrets-report

WSU Analyst Remark:
The suspected Chinese state sponsored group has focused on engineering and maritime entities with malware designed to establish presence on victim networks and exfiltrate credentials and data, likely in support of Chinese political, military, and economic interests. Given recent tensions between China and the U.S., and China’s ongoing dispute with regional and global actors over the South China Sea, It is not a surprise that Chinese espionage actors demonstrate a high interest in maritime entities.