// CPCSC TEMPLATES · 05 OF 14

Password and authentication policy

Last verified: 2026-10-05

One page. Written to clear 03.05.03 and 03.05.07 at a small shop, then applied and screenshotted so the written policy and the enforced one match.

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-05 Static template

Policy

Passwords on [Company] systems holding Specified Information are at least [14] characters. Passphrases are encouraged; composition rules beyond length are not enforced. New and changed passwords are screened against a list of commonly used and breached passwords, updated [quarterly] and whenever a compromise is suspected. Passwords are never reused across systems, are transmitted only over encrypted channels, and are stored only as salted hashes.

Accounts lock after [10] failed attempts for [15 minutes]. A new password is set at first use after any account recovery. Default credentials on any device or application are changed before it joins the network.

Multifactor authentication is required for all remote access, all privileged accounts, all cloud administration, and all enclave logins, privileged and non-privileged. Hardware keys are preferred; authenticator apps are accepted; SMS is not.

Shared accounts are prohibited on systems holding Specified Information. Authenticators lost, stolen, or suspected compromised are reported to [role] the same day and revoked.

Owner: [name, role]. Reviewed: [date]. Applied-policy screenshot on file: [date].

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.