Ohio Admin. Code 5101:9-9-37 - Data system security
The following requirements ensure the security of departmental data and must be followed by all county and state employees (hereafter referred to as 'user' or 'users') who access data systems maintained by the office of information services (OIS) and the Ohio department of job and family services (ODJFS) via the private or public network.
(B) Passwords must remain
confidential and be eight characters or longer in length and have each of the
following characteristics:
(1) At least one
number.
(2) At least one special
character.
(3) At least one upper case
letter.
(4) At least one lower case
letter.
(C) Passwords are valid for a
maximum of sixty days and shall not be repeated for a twelve month
period.
(D) Password resets executed by OIS
support staff or county technical points of contacts (TPOCs) must require the
user to change their password upon next login.
(E) Users must not change their
passwords more than once per day.
Notes
Promulgated Under: 111.15
Statutory Authority: 5101.02, 329.04
Rule Amplifies: 5101.02, 329.04
Prior Effective Dates: 03/18/1988 (Emer.), 06/10/1988, 06/15/1998, 07/01/2005, 01/01/2016
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.