This ensures that passwords meet the technically verifiable criteria for length and character types. The aim is to work together to increase the long-term protection of our digital infrastructure and sensitive data.
“By using a secure password, we all play a part in safeguarding the university’s operational capacity and ensuring the reliable availability of its services. IT security is a shared responsibility between the university and all its users,” explains Rainer Jantscher, Head of the IT Core Services, Security & Privacy department and Deputy Head of the ZID.
What requirements must a password meet?
As of 1 September, a ZID password must meet the following criteria:
- At least 12 characters in length
- Contains at least 1 upper-case letter and 1 lower-case letter, and additionally 1 digit or 1 special character
Is not identical to a UserID
Differs significantly from other passwords (such as those used for social media or online shops) as well as the previous ZID password – specifically avoiding sequential numbers (2024, 2025, 2026…)
Is not reused across multiple accounts
Is not easy to guess
Is not listed in common password dictionaries
Follows best practices
“These are the minimum requirements for secure IT operations. The password should be as long and as random as possible; in particular, it should not contain simple patterns like 12345. We therefore recommend using a password manager to generate secure passwords and store them securely. A secure password – ideally in combination with a password manager—makes it significantly harder for attackers,” says Kerstin Ammann-Silvaggio, Head of the IT Security team of the ZID.
All password requirements and best practices are available in the password terms of use. Users can also access the password tips of the ZID.