Password Policy
Draft template. This is generic starting content, not a reviewed or binding company policy. Have Legal review and approve before publishing externally.
Minimum requirements
- Minimum password length and complexity as enforced by the platform.
- Passwords must not be shared between users.
- Multi-factor authentication (MFA) is recommended, and required for administrative accounts where supported.
- Passwords should be changed immediately if compromise is suspected.
Account lockout
Accounts are typically locked after a defined number of failed login attempts, to prevent brute-force attacks.