The Password Policy details how
passwords must be managed to ensure that they are protected and secure. The
policy provides guidance on password management which includes: -
· The sharing of passwords
· Changing passwords
· How to ensure the security of passwords e.g.,
making them unique and difficult to guess
· How to safely store password
The Password and Secure Authentication Policy places a stronger emphasis on the use of secure authentication controls.
Also supplied is the P-27A_Password-and-Secure-Authentication_Policy which is the policy with additional reference to secure authentication.
These policies have relevance for and can contribute towards an ISO 27001:2022 compliant management system.
The information classification label on this policy is [Public].