Each database account should have its password changed from the default. For
application-owned accounts this needs to be in two stages – the first is to change
the password through the Oracle Applications system administrator function, the
second is to change the database password at the database level. If one of these
stages is not performed, an inconsistency will occur and problems will arise.
Management should implement a policy such that all passwords are changed at
least twice a year, with the passwords for key accounts changed at least every
90 days. Documentation should be maintained in order to confirm compliance
with this procedure.