Password Policy
** Draft template.** This is generic starting content, not a reviewed or binding company policy. Have Legal review and approve before publishing externally.
Minimum requirements
-
Minimum password length and complexity as enforced by the platform.
-
Passwords must not be shared between users.
-
Multi-factor authentication (MFA) is recommended, and required for administrative accounts where supported.
-
Passwords should be changed immediately if compromise is suspected.
Account lockout
Accounts are typically locked after a defined number of failed login attempts, to prevent brute-force attacks.