


For departmental/faculty use of a password manager, a Privacy Impact Assessment (PIA) must be completed prior to use. Below are some of the industry-leading/popular products.These combine the benefits of standalone and web-based systems. Newer services offer a dual environment, with device-based apps that are synched to the cloud. Many password safes now offer to import the browser passwords lists. Browsers are subject to constant attack and there are known vulnerabilities that can expose passwords stored in browsers. Most web browsers have the ability to “Remember this password” for secure login sites. However if the site is inaccessible or no Internet connection is available, then the passwords will not be accessible. With these services, the data is not susceptible to database corruption or loss of the device. These are accessible through a web browser and are stored online as part of a cloud service. However, if the device is lost or the database corrupted, then the only way to recover the data will be through a backup copy. With these services, the data is accessible no matter if an internet connection is available or not. These are installed on the desktop or on your mobile device as an application. Here is a summary of the available options: Picking a Password Safe can be tricky.If it is lost or forgotten, UBC cannot recover or bypass it. Users are responsible for remembering the master passphrase/password.The master passphrase/password must be changed at least annually.Refer to the Passphrase and Password Protection standard for information on how to design a secure passphrase/password. The master passphrase/password used to protect the Password Safe must be strong otherwise the security of the safe and all of its contents are at risk.Questions about this guideline may be referred to Passphrases/Passwords Compliance with this guideline is recommended, but not mandatory.

This guideline has been issued by the Chief Information Officer to supplement the Passphrase and Password Protection standard.Password Safes are simple to use because they can be accessed with a single master passphrase/password. Password Safes (or Password Managers) are computer applications that provide a secure place to store and access the passphrases/passwords for different login environments.Information Security Guideline Introduction
