Skip to main content

ER-45 Password Policy and Configurations

C
Written by Claudio Morsella
Updated over a month ago

Password and MFA Policy

Provide your password and authentication policy for all in-scope production systems.

Password Configurations for All In-Scope Production Systems

Provide system screenshots displaying the password configurations for all in-scope production systems.

For each of your in-scope production systems, the evidence should demonstrate:

  • Password character minimum lengths

  • Password expiration requirements

  • Password complexity requirements

  • Password lockout configurations

Additional Guidance
Your password and authentication policy is typically covered by your Information Security Policy.

Associated Unified Control ID

Associated Framework Control

CTRL-349

LCL-33

Did this answer your question?