Password and MFA Policy
1. Purpose
This policy establishes minimum requirements for protecting company accounts through secure passwords, password management, and multi-factor authentication.
2. Unique Passwords
Passwords used for company accounts must be unique.
Users must not reuse company passwords on personal websites or unrelated services.
3. Password Managers
The company should provide or approve a password manager.
Users should use the password manager to create and store strong, unique passwords.
Passwords should not normally be stored in:
- Spreadsheets
- Chat messages
- Unprotected documents
- Paper notes left in insecure locations
4. Password Strength
Where systems permit, use long passwords or passphrases.
The company should favor length and uniqueness rather than requiring frequent arbitrary password changes or complicated patterns that encourage predictable passwords.
Passwords should be changed when:
- Compromise is suspected.
- Credentials were exposed.
- A system requires a security-driven reset.
- A shared or emergency credential must be rotated.
5. Multi-Factor Authentication
MFA should be required wherever practical, with priority given to:
- Administrator accounts
- Cloud services
- Remote access
- VPN
- Finance systems
- Payroll systems
- Backup systems
- Password managers
- Domain registrars
- DNS providers
- Security tools
- Vendor and MSP administrative access
6. MFA Methods
Where practical, stronger MFA methods should be preferred.
Examples include:
- Hardware security keys
- Passkeys
- Authenticator applications
- Number matching or equivalent push verification
SMS may be used where stronger options are unavailable, but stronger methods should be preferred for high-risk accounts.
7. Unexpected MFA Prompts
Users must never approve an MFA prompt they did not initiate.
Unexpected prompts should be:
- Denied
- Reported immediately
- Investigated as possible credential compromise
8. Account Recovery and MFA Reset
Password resets and MFA resets for sensitive accounts should require appropriate identity verification.
High-risk resets should not rely only on an email, chat message, or phone call from an unknown number.
Administrative and executive account recovery should receive additional verification.
9. Shared Credentials
Shared credentials should be avoided.
Where unavoidable:
- Assign an owner
- Store the credential in an approved password manager
- Limit access
- Enable MFA where possible
- Rotate credentials when authorized users change
- Review the continued need for the shared credential
10. Privileged Accounts
Administrator credentials should:
- Be unique
- Use MFA
- Be stored securely
- Not be shared casually
- Be separated from ordinary user accounts where practical
- Not be used for normal web browsing or email
11. Compromised Credentials
If a password may have been exposed:
- Report it immediately.
- Revoke suspicious sessions where possible.
- Reset the credential.
- Review MFA settings.
- Review recovery methods.
- Check for suspicious account activity.
Do not simply change the password and assume the incident is finished.
Practical Rule
Every important account should have a unique credential and MFA.
One compromised password should not unlock the rest of the company.