Policy
Passwords on [Company] systems holding Specified Information are at least [14] characters. Passphrases are encouraged; composition rules beyond length are not enforced. New and changed passwords are screened against a list of commonly used and breached passwords, updated [quarterly] and whenever a compromise is suspected. Passwords are never reused across systems, are transmitted only over encrypted channels, and are stored only as salted hashes.
Accounts lock after [10] failed attempts for [15 minutes]. A new password is set at first use after any account recovery. Default credentials on any device or application are changed before it joins the network.
Multifactor authentication is required for all remote access, all privileged accounts, all cloud administration, and all enclave logins, privileged and non-privileged. Hardware keys are preferred; authenticator apps are accepted; SMS is not.
Shared accounts are prohibited on systems holding Specified Information. Authenticators lost, stolen, or suspected compromised are reported to [role] the same day and revoked.
Owner: [name, role]. Reviewed: [date]. Applied-policy screenshot on file: [date].