Tutorials/Password Policy

Password Policy

Document control

Field Value
Document status Active policy document
Owner Security / Operations
Approver Management
Review frequency Annual or on material change
Classification Customer-shareable

Purpose

Define password and authentication requirements to reduce account compromise risk.

Password requirements

Passwords must be unique, difficult to guess, and not reused across unrelated systems. Default passwords must be changed before production or customer use. Passwords must not be shared, written in public channels, or stored in plaintext.

MFA

MFA should be enabled for administrative, cloud, repository, email, finance, customer-support, and other sensitive access where supported.

Storage and transmission

Applications must store passwords using secure hashing mechanisms. Temporary passwords or reset links must expire and be transmitted through approved channels.

Password reset

Password reset processes must verify the user's authority and avoid exposing account information. Administrative resets should be logged.

Compromise handling

Suspected compromised passwords must be reset promptly. Related sessions, tokens, and API keys should be reviewed and revoked where necessary.

Evidence to maintain

Password policy, MFA configuration evidence, reset logs, default-password checklist, and incident records.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.