Skip to main content Skip to navigation
Washington State University
Information Technology Services

Welcome to Information Security Services

Information Security Services within the ITS group at Washington State University consists of two teams, the Security Operations Center (SOC) and Governance, Risk and Compliance (GRC).

The Security Operations Center works around the clock to protect the data resources of students, faculty and staff, as well as protecting the confidentiality, integrity, and availability of information important to the university’s mission. These processes are completed through management and monitoring of numerous industry-best security applications and tools. This group also monitors WSU’s customer support email that assists with community questions regarding the safety of emails and attachments.

Governance, Risk and Compliance assists in mitigating security risks to information technology assets at the University, improves security of system and network services, proactive risk management, and crisis and security incident management. This team provides security and risk assessments, evaluating the security controls within an information system to determine the controls are implemented correctly, operating as intended, and producing the desired outcome. The GRC group also provide security consulting on demand for WSU business units.

For a comprehensive list of all provided services, please check the Information Technology Service Catalog.


How to change your password

Password Assistance

WSU Password Policy

As described in the existing WSU Executive Policy 18, passwords will be required to be reset every 180 days, starting at the date of your most recent password change.


Once you have reset your password, you will need to update your account information for wireless internet access and applications on your mobile devices.

Failure to do so may result in your account being locked out due to multiple failed attempts to connect with your account.

Change or Recover Network ID

To change your WSU Network ID, Friend ID or Password

Please go to and log in to begin changing your password.

  • As an added security precaution, faculty and staff will be asked two security questions before being allowed to change their password: start date at WSU and the approximate gross amount of their last paycheck.
  • Once you have started the process, you will have 15 minutes to complete your password reset, then the session will time out.

To Recover your WSU Network ID or Friend ID

  • Call Crimson Service Desk at 509-335-4357

Tri-Cities Account

To change the password for your Tri-Cities account

Please go to and fill out the form.

You can also reset your local WSUTC account via the following method:

  • Log in to your workstation
  • After it has booted up, press Ctrl/Alt/Delete and click on “Change a Password.”
  • Follow the instructions on the screen.

VetMed Account

To change the password for your VetMed account (

Please contact the VetMed IT help desk.

Password Requirements

Minimum Characters8
Letter - Number - Special Characters (i.e., !, @, #, $, ?)At least 1 of each
Case SensitiveYes
Character Change Requirement for PW Resets3 characters must change
Password Expiration180 Days
Inactivity Deactivation Threshold90 Days
Lockout Policy5 Consecutive Failures
Lockout Duration5 minutes

Tips & Tricks

How to create a strong password that you can remember

Avoid names, places, family, pets, and dictionary words.

KardashianFan, Cancun, George, Fido, and any word you could look up in a dictionary are right out. They’re too easy for people to guess, and hackers can build programs that automatically try known words.

Instead, use abbreviated phrases and multiple words or fragments of words. Substitute numbers and special characters for letters or entire words to break up patterns—make it easy to remember, but impossible for anyone else to guess.

Connect the first letters of a passphrase:

  • 1ibLn+Tib5e = One if by land, two if by sea

Take a sentence and turn it into a password:

  • WOO!TSwontSB = Woohoo! The Seahawks won the Super Bowl!
  • PPupmoarT@O@tgs = Please pick up more Toasty O’s at the grocery store.
  • W?ow?imp::ohth3r = Where oh where is my pear? Oh, there.

Nursery rhyme:

  • HD504w,HDh4gf = Humpty Dumpty sat on a wall, Humpty Dumpty had a great fall.

Favorite line of a song or movie:

  • yMw4h4yF50e!! = Your mother was a hamster and your father smelled of elderberries!

Use a Keyboard Pattern:

  • #WAxcvgy7890-

Consider doubling an easier password:

  • B04t5xB04t5! = Boats x Boats

Reverse any of the above.


Phishing is an attempt to trick you into revealing private information. Emails, texts, or phone calls can “fish” for information by trying to lure you into clicking on a malicious link or attachment, or giving passwords, credit card numbers, etc., to a malicious third party. Report suspicious emails and phishing scams to


  • Legitimate companies do not ask for personal info via email or text.
  • Messages may appear to be from organizations you do business with.
  • Sense of urgency: Messages may include threatening statements to close an account if you fail to respond, often indicating that such threats will be executed “immediately.”
  • Obvious grammatical errors, spelling errors, and strange word choices. Messages from legitimate companies are usually written by professional communicators who won’t make such errors.


  1. Sender’s email address: Official WSU communications will always be sent from a address. However be cautious, just because it does come from a address does not guarantee that it is legit either.
  2. Impersonal or awkward greeting: Most phishing emails do NOT refer to the recipient by name.
  3. Spelling: Official emails should not have spelling or grammatical mistakes.
  4. Ultimatum: Urgent warning attempts to scare you into responding quickly and without thought.
  5. WSU will never ask for your password or other personal information via email.
  6. Bogus URL: Official WSU websites will always end in Website URLs are easily obscured. DO NOT click. Instead, hover over the link to verify destination URL.
  7. Security disclaimer: This does not mean the message is genuine.
  8. No signature or contact info: Official WSU business will always include WSU phone, email, and web address.


Sample phishing email:


  • If you think the message might be legitimate, or if you’re worried about the consequences of ignoring it, look up the organization independently and contact them directly.
  • Do not click on links or call phone numbers provided in the message. They may redirect you to fake sites that mimic the real thing.
  • Do not open attachments that are unexpected or from unverified sources.
  • Do not send your password via email.
  • Only sign in if you are 100% sure you are on the real site.
  • Report suspicious emails and phishing scams to


Any unprotected computer connected to the internet is likely to be infected within minutes. Malware infections put your personal data—and everyone you’re connected to—at risk.


  • Keep your system up to date
  • Use anti-virus software
  • Do not install untrusted software



  • Change of browser homepage/start page
  • Changed settings which cannot be changed back
  • Ending up at a strange site when using search
  • System firewall has been turned off
  • Increased network activity while not active
  • Excessive pop-up windows
  • New icons, programs, or favorites which you did not add
  • Frequent firewall alerts about unknown programs
  • Bad/slow system performance


Policies, Standards and Guidelines

WSU’s Information Security Program (ISP) is managed and operated by the central Information Technology Services Department (ITS) of WSU. Within ITS the ISP has a broad role and responsibility with respect to information security and privacy across the Institution. The mission of WSU’s ISP is to provide clear and flexible information security and privacy policies, procedures, standards, and risk mitigations to enable Washington State University to safely carry out its mission and accomplish its strategic goals.

The Program exists to appropriately protect, maintain, and ensure legal, compliant, and appropriate use of the university’s information technology assets. Security and privacy policies work together to lay the foundation for the campus community to build and operate a high quality and trusted campus computing environment.

To complement the requirements outlined in WSU Business Policies and Procedures Manuals (BPPM) and WSU Executive Policy Manuals (EP)., ISS has created supplemental policies, standards, guidelines, procedures, and forms designed to ensure campus compliance with applicable policies, laws and regulations.

All users and campus departments are expected to help safeguard and secure campus information and information resources by adhering to these policies and standards where applicable, or to request an exception.

Please report suspected violations to


Chinese Government Hackers Reportedly Stole Trove of Sensitive U.S. Naval Data:
A new report claims that Chinese government hackers stole more than 614 gigabytes of sensitive data from a U.S. Navy contractor. The attacks occurred in January and February and were conducted by a division of the Chinese Ministry of State Security. The target was a contractor that works for the Naval Undersea Warfare Center and conducts research and development for submarines and underwater weapons systems. The stolen data is said to include secret plans to develop a new submarine-launched anti-ship missile as well as information about sensors and submarine cryptographic systems. Chinese hackers have frequently targeted U.S. military contractors and have previously succeeded in stealing information about the new F-35 stealth fighter, the advanced Patriot PAC-3 missile system, and other sensitive projects.

Entire Article:

WSU Analyst Remark:
The suspected Chinese state sponsored group has focused on engineering and maritime entities with malware designed to establish presence on victim networks and exfiltrate credentials and data, likely in support of Chinese political, military, and economic interests. Given recent tensions between China and the U.S., and China’s ongoing dispute with regional and global actors over the South China Sea, It is not a surprise that Chinese espionage actors demonstrate a high interest in maritime entities.