MEMORANDUM <br /> TO: EDUCATION DEPARTMENT CENTRAL AUTOMATED PROCESSING <br /> SYSTEM (EDCAPS) USER <br /> FROM: ROGER GOODSON, EDCAPS COMPUTER SECURITY OFFICER <br /> SUBJECT: EDCAPS USER ID AND PASSWORD <br /> Your application for an EDCAPS user ID has been approved. Your user ID and initial <br /> password are attached. You should memorize the password and destroy the attachment. You are <br /> reminded to log on and change your password as soon as possible. If you are not able to log on and <br /> change your initial password promptly, notify the applicable security administrator. You should <br /> select a password with a minimum character length of 8 and it should consist of alpha, special and <br /> numeric characters. Your are also required to change this password periodically, not to exceed 90 <br /> days. When you no longer require access to EDCAPS applications (or you are reassigned to a <br /> different Principle Office), notify your applicable security administrator immediately so that your <br /> account can be updated as necessary. <br /> All EDCAPS users are required to read, understand, and implement the following. <br /> a. Use ED computing resources only for official Government business: <br /> b. Know whom my site computer security personnel and how they can be contacted; <br /> c. Know the sensitivity of the information processed on EDCAPS computing resources (e.g., <br /> financial sensitive, Privacy Act sensitive); <br /> d. Use software only in compliance with licensing agreements and which has been authorized for use <br /> by management; <br /> e. Protect sensitive information from access by, or disclosure to, unauthorized personnel; <br /> f. Report immediately all security incidents and potential threats and vulnerabilities involving <br /> computing resources to designated computer security personnel; <br /> g. Create and use strong passwords, do not recycle passwords and do not disclose your password to <br /> anyone. Users are requested to log -off applications when they are done using them and to not leave <br /> their PCs unattended. In addition, users are requested to use the Windows screensaver feature with <br /> password feature enabled to protect unattended terminals (set to 5 minutes); <br /> h. Report any compromise or suspected compromise of a password to designated computer security <br /> personnel; <br /> i. Access only systems, networks, data, and software for which I have been authorized; <br /> j. Ensure that system media and system output are marked according to their sensitivity and are <br /> properly controlled and stored; <br /> k. Inform EDCAPS security management when access to an EDCAPS computing resource is no <br /> longer required such as when I complete a project, transfer to another position, or terminate <br /> employment; <br /> I. Take necessary steps to avoid the introduction of malicious code into any computing resource; <br /> m. Exercise due diligence to prevent physical damage to and theft of any Departmental computing <br /> resource; <br /> n. Notify management before relocating computing resources. <br /> Although you are directed to memorize and destroy the password attachment, you should keep this <br /> letter and review your security responsibilities frequently. If you have any questions, please call me <br /> on (202) 401 -0108. Thank you. <br /> Updated 5/16/00 <br />