Password and MFA Policy
Provide your password and authentication policy for all in-scope production systems.
Password Configurations for All In-Scope Production Systems
Provide system screenshots displaying the password configurations for all in-scope production systems.
For each of your in-scope production systems, the evidence should demonstrate:
Password character minimum lengths
Password expiration requirements
Password complexity requirements
Password lockout configurations
Additional Guidance
Your password and authentication policy is typically covered by your Information Security Policy.
Associated Unified Control ID | Associated Framework Control |
CTRL-349 | LCL-33 |