What to Provide
Password and authentication policy for all in-scope production systems.
System screenshots displaying the password configurations for all in-scope production systems.
For each of your in-scope production systems, the evidence should demonstrate:
Password character minimum lengths
Password expiration requirements
Password complexity requirements
Password lockout configurations
Evidence Format
Document(s) in a common document file type such as .pdf or .doc.
Additional Guidance
Your password and authentication policy is typically covered by your Information Security Policy.
Associated Unified Control ID | Associated Framework Control |
CTRL-349 | LCL-33 |