Password and MFA Policy

1. Purpose

This policy establishes minimum requirements for protecting company accounts through secure passwords, password management, and multi-factor authentication.

2. Unique Passwords

Passwords used for company accounts must be unique.

Users must not reuse company passwords on personal websites or unrelated services.

3. Password Managers

The company should provide or approve a password manager.

Users should use the password manager to create and store strong, unique passwords.

Passwords should not normally be stored in:

  • Spreadsheets
  • Email
  • Chat messages
  • Unprotected documents
  • Paper notes left in insecure locations

4. Password Strength

Where systems permit, use long passwords or passphrases.

The company should favor length and uniqueness rather than requiring frequent arbitrary password changes or complicated patterns that encourage predictable passwords.

Passwords should be changed when:

  • Compromise is suspected.
  • Credentials were exposed.
  • A system requires a security-driven reset.
  • A shared or emergency credential must be rotated.

5. Multi-Factor Authentication

MFA should be required wherever practical, with priority given to:

  • Email
  • Administrator accounts
  • Cloud services
  • Remote access
  • VPN
  • Finance systems
  • Payroll systems
  • Backup systems
  • Password managers
  • Domain registrars
  • DNS providers
  • Security tools
  • Vendor and MSP administrative access

6. MFA Methods

Where practical, stronger MFA methods should be preferred.

Examples include:

  • Hardware security keys
  • Passkeys
  • Authenticator applications
  • Number matching or equivalent push verification

SMS may be used where stronger options are unavailable, but stronger methods should be preferred for high-risk accounts.

7. Unexpected MFA Prompts

Users must never approve an MFA prompt they did not initiate.

Unexpected prompts should be:

  • Denied
  • Reported immediately
  • Investigated as possible credential compromise

8. Account Recovery and MFA Reset

Password resets and MFA resets for sensitive accounts should require appropriate identity verification.

High-risk resets should not rely only on an email, chat message, or phone call from an unknown number.

Administrative and executive account recovery should receive additional verification.

9. Shared Credentials

Shared credentials should be avoided.

Where unavoidable:

  • Assign an owner
  • Store the credential in an approved password manager
  • Limit access
  • Enable MFA where possible
  • Rotate credentials when authorized users change
  • Review the continued need for the shared credential

10. Privileged Accounts

Administrator credentials should:

  • Be unique
  • Use MFA
  • Be stored securely
  • Not be shared casually
  • Be separated from ordinary user accounts where practical
  • Not be used for normal web browsing or email

11. Compromised Credentials

If a password may have been exposed:

  • Report it immediately.
  • Revoke suspicious sessions where possible.
  • Reset the credential.
  • Review MFA settings.
  • Review recovery methods.
  • Check for suspicious account activity.

Do not simply change the password and assume the incident is finished.

Practical Rule

Every important account should have a unique credential and MFA.

One compromised password should not unlock the rest of the company.