PJM has the responsibility to ensure the integrity and confidentiality of the systems and data (provided by members or derived by PJM) at PJM. In pursuing this responsibility, PJM employs a variety of security techniques at PJM including the use of strong passwords to authorize user requests for access to data and systems. PJM is currently requiring the use of strong passwords through a set of rules in place for the PJM members using the
EES system.
With the initial release of the PJM
Market User Interface (MUI) the use of strong passwords will also apply to
Open Access Same-Time Information System (OASIS) users who log on to the
OASIS system. As PJM extends the use of the MUI to provide a single interface to PJM members, the use of strong passwords will be required for the additional applications accessible through the MUI.
PJM Policy and the associated rules that define how a password must be composed define strong passwords. The rules that are in effect through the PJM MUI are:
Usernames
- Must be at least 6 characters
- Must be unique across all users and companies
- The first character of a username cannot be a special character
Passwords
- Must contain at least one upper case and one lower case letter
- Must contain a numeral
- Must contain one special character -- valid special characters include: ()!$`~:.,<>=?^_{}[]|
- Password length of at least 8 characters and not more than 16 characters
- Username cannot be part of your password
- Cannot use the same password for 15 generations
- The first character of password cannot be a special character
- PJM members are encouraged to follow good password practices to protect their data at PJM from inappropriate access at their locations. Reasonable password practices suggested for use by
PJM members include:
- Use a different password for each application
- Change your password to each application at a regular frequency, such as 60 days
- Never write passwords down
- Do not share passwords with other users
- Remove user IDs and passwords from PJM applications if a person at the company changes their job function or leaves the company
- Do not use a common user id and password for many people to access a PJM application unless absolutely required for business purposes