security-policy-as-code-framework-model

1. Overview

This standard supports the Access Control Policy by defining the minimum mandatory requirements for all user and system account passwords. Its purpose is to reduce the risk of unauthorized access through compromised credentials.

2. Scope

This standard applies to all passwords used to authenticate to any company-owned or managed system, application, or service, for all user types including employees, contractors, customers, and system accounts.

3. Standard Requirements

3.1. User Passwords

All passwords for interactive user accounts must meet the following criteria:

3.2. System and Service Account Passwords

3.3. Multi-Factor Authentication (MFA)

MFA must be enabled on all user accounts where it is supported, especially for access to Restricted or Confidential data, and for all remote access to the corporate network.

4. Enforcement

Compliance with this standard will be enforced at a technical level by the respective systems and applications. The Security Engineering team will periodically audit systems to ensure they are configured to enforce these requirements. Accounts found to be non-compliant may be disabled until they are brought into compliance.