Password Policy
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define password and authentication requirements to reduce account compromise risk.
Password requirements
Passwords must be unique, difficult to guess, and not reused across unrelated systems. Default passwords must be changed before production or customer use. Passwords must not be shared, written in public channels, or stored in plaintext.
MFA
MFA should be enabled for administrative, cloud, repository, email, finance, customer-support, and other sensitive access where supported.
Storage and transmission
Applications must store passwords using secure hashing mechanisms. Temporary passwords or reset links must expire and be transmitted through approved channels.
Password reset
Password reset processes must verify the user's authority and avoid exposing account information. Administrative resets should be logged.
Compromise handling
Suspected compromised passwords must be reset promptly. Related sessions, tokens, and API keys should be reviewed and revoked where necessary.
Evidence to maintain
Password policy, MFA configuration evidence, reset logs, default-password checklist, and incident records.