This standard supports the Access Control Policy by defining the minimum mandatory requirements for all user and system account passwords. Its purpose is to reduce the risk of unauthorized access through compromised credentials.
This standard applies to all passwords used to authenticate to any company-owned or managed system, application, or service, for all user types including employees, contractors, customers, and system accounts.
All passwords for interactive user accounts must meet the following criteria:
Special characters (~!@#$%^&*_-+= |
\(){}[]:;”’<>,.?/`) |
MFA must be enabled on all user accounts where it is supported, especially for access to Restricted or Confidential data, and for all remote access to the corporate network.
Compliance with this standard will be enforced at a technical level by the respective systems and applications. The Security Engineering team will periodically audit systems to ensure they are configured to enforce these requirements. Accounts found to be non-compliant may be disabled until they are brought into compliance.