NSBTM Password Management

Josh Bergman (our website designer) has recommended that maintaining a document on our website that contains the passwords NSBTM Board Members need to do business, as was done in the past, is anextremely unwise and high security risk.

The Board Chair, Board Treasurer and Web Content Editor have access to all passwords.

These are the passwords currently in use, sorted by Job Descriptions:

Chair

  • All Passwords
  • (for NSBTM related email, if desired)

Vice Chair

  • MailChimp (mails newsletters)

Secretary

  • PayPal (transfers PayPal balances to Key Bank)
  • MailChimp (puts content online for new newsletters)

Treasurer

  • All passwords but especially:
  • (for accounting related email)
  • GoDaddy.com account for Domain Registration
  • Online QuickBooks (for all financial recordkeeping)
  • IRS Form 990 e-reporting website
  • Key Bank Checking Account
  • Key Bank Debit Card numbers, expiry dates and security codes
  • PayPal
  • TotalChoice Hosting

Skype Conference Call Host

  • Skype password for “nsbtm.meetings”
  • Microsoft Account (linked to nsbtm.meetings)

Webmaster (sets up and administers the server; updates server configurations; installs server-based applications like online stores) – this is Josh Bergman

  • GoDaddy.com account (for Domain Registration)
  • Website Control Panel
  • Website Store Admin
  • PayPal
  • TotalChoice Hosting

Web Designer (creates templates for the site; organizes and sets up pages and link structure) – this is also Josh Bergman

  • Website Control Panel
  • Website Store Admin

Web Content Editor (adds the content to the site; updates content as necessary; responds to site inquiries submitted via the Contact Us form; reports on site traffic;reports website, store or software problems to the Webmaster to be fixed; sets up access privileges and manages users)

  • Maintains and distributes the PasswordSafe database
  • All passwords but especially:
  • (for website related email)
  • Backup for GoDaddy.com account (for Domain Registration)
  • Google Analytics
  • MailChimp (sends Welcome letters to new Friends of TM)
  • Website Control Panel (for accessing the backend of the website)
  • Website Store Admin

Web Content Manager Assistant (anyone else who may help with updating the website)

  • Access to the website Board Room

Facebook Page Administrators – Currently Mary Stephens and Jefferson Svengsouk

  • These Administrators use their own Facebook passwords to access the NSBTM Facebook Page

Every Board Member has their own password to the Board Room (created by the Web Content Editor) which is not saved anywhere after it is sent to them.

The Web Content Editor controls all NSBTM Passwords which are currently maintained in Password Safe, a password management program which runs on PC, Mac, iPadand Linux platforms. The software is installed locally and the passwords are stored on the local machine, not in the “Cloud” which is safer from hackers. Updated copies of the PasswordSafe file are distributed to the Chair and Treasurer.