Some good practices include:

See these topics:

Changing Default ORACLE Passwords (UNIX)

Changing Default ORACLE Passwords (WINDOWS OS)