Skip to main content

ER-45 Password Policy and Configurations

C
Written by Claudio Morsella
Updated over a year ago

What to Provide

Password and authentication policy for all in-scope production systems.

System screenshots displaying the password configurations for all in-scope production systems.

For each of your in-scope production systems, the evidence should demonstrate:

  • Password character minimum lengths

  • Password expiration requirements

  • Password complexity requirements

  • Password lockout configurations

Evidence Format
Document(s) in a common document file type such as .pdf or .doc.

Additional Guidance
Your password and authentication policy is typically covered by your Information Security Policy.

Associated Unified Control ID

Associated Framework Control

CTRL-349

LCL-33

Did this answer your question?