Policy Statement
The Company is committed to maintaining the confidentiality, integrity, and availability of its information assets. This Password & Authentication Policy establishes the standards for creating, managing, and securing passwords and authentication mechanisms across all Company systems and applications.
Objectives
- Define the minimum requirements for password complexity and authentication methods.
- Prevent unauthorized access to Company systems and data.
- Promote secure authentication practices for employees, contractors, and third-party users.
- Ensure compliance with ISO 27001, GDPR, and DPDP Act security standards.
Scope and Applicability
This policy applies to all employees, contractors, consultants, vendors, and third parties who have access to the Company's IT systems, networks, or data. It applies to all devices and platforms including desktops, laptops, mobile devices, and cloud-based systems.
Turn this template into a living policy
Book a 20-minute demo to see how PolicyCentral.ai distributes, translates, and tracks acknowledgement of policies like this across your entire workforce.
Book a DemoPassword Creation Requirements
- Passwords must contain a minimum of 12 characters.
- Must include at least one uppercase letter, one lowercase letter, one number, and one special character.
- Must not contain easily guessable information (e.g., name, birthdate, or common words).
- Must be unique and not reused across multiple systems or accounts.
- Default or vendor-provided passwords must be changed immediately upon account setup.
Authentication Mechanisms
- Multi-Factor Authentication (MFA) must be enabled for all critical systems and remote access.
- Biometric authentication (fingerprint, facial recognition) may be used where available and approved.
- Shared accounts are prohibited; each user must have a unique login credential.
- Privileged accounts must use stronger authentication controls and may require hardware-based tokens.
Password Management and Storage
- Passwords must be stored using strong encryption or hashing mechanisms (e.g., SHA-256 or better).
- Employees must not write down, share, or email passwords in plain text.
- Passwords must be changed at least every 90 days or immediately after suspected compromise.
- Systems must enforce automatic account lockout after five (5) failed login attempts.
- Password recovery processes must include secure identity verification steps.
System and Application Controls
- All Company systems must enforce password complexity and expiration rules.
- Session timeouts must automatically log out inactive users after 15 minutes of inactivity.
- Users accessing cloud or remote systems must authenticate via secure VPN and MFA.
- Administrative and privileged credentials must be rotated regularly and monitored.
User Responsibilities
- Protect login credentials from disclosure or unauthorized access.
- Log out or lock systems when leaving workstations unattended.
- Report suspected password compromise or suspicious activity to the IT Security Department immediately.
- Use Company-approved password management tools where applicable.
Non-Compliance
Non-compliance with this policy, including sharing passwords or failing to follow authentication procedures, may result in disciplinary action, up to and including termination of employment. Repeated or intentional violations may also lead to legal consequences under applicable data protection laws.
Policy Review
This policy shall be reviewed annually or whenever there are changes in security regulations, technology, or business operations. Revisions must be approved by the Board of Directors and communicated to all employees.
Employee Acknowledgment
I acknowledge that I have read and understood the Password & Authentication Policy of the Company I agree to comply with the requirements of this policy and understand that failure to do so may result in disciplinary action.
Employee Name: __________________________
Signature: ______________________________
Date: _________________________________
Browse all policy categories
Frequently asked questions
Who does this policy apply to?
This policy applies to all employees, contractors, consultants, vendors, and third parties who have access to the Company's IT systems, networks, or data. It applies to all devices and platforms including desktops, laptops, mobile devices, and cloud-based systems.
What does the authentication mechanisms cover?
Multi-Factor Authentication (MFA) must be enabled for all critical systems and remote access. Biometric authentication (fingerprint, facial recognition) may be used where available and approved. Shared accounts are prohibited; each user must have a unique login credential. Privileged accounts must use stronger authentication controls and may require hardware-based tokens.
Who is responsible for implementing this policy?
Protect login credentials from disclosure or unauthorized access. Log out or lock systems when leaving workstations unattended. Report suspected password compromise or suspicious activity to the IT Security Department immediately. Use Company-approved password management tools where applicable.
What happens in case of non-compliance?
Non-compliance with this policy, including sharing passwords or failing to follow authentication procedures, may result in disciplinary action, up to and including termination of employment. Repeated or intentional violations may also lead to legal consequences under applicable data protection laws.
How often is this policy reviewed?
This policy shall be reviewed annually or whenever there are changes in security regulations, technology, or business operations. Revisions must be approved by the Board of Directors and communicated to all employees.