Skip to main content

ER-45 Pre-Kickoff - Password Policy and Configurations

Suzette Richards avatar
Written by Suzette Richards
Updated this week

Password and MFA Policy

Provide your password and authentication policy for all in-scope production systems.

Password Configurations for All In-Scope Production Systems

Provide system screenshots displaying the password configurations for all in-scope production systems.

For each of your in-scope production systems, the evidence should demonstrate:

  • Password character minimum lengths

  • Password expiration requirements

  • Password complexity requirements

  • Password lockout configurations

Additional Guidance
Your password and authentication policy is typically covered by your Information Security Policy.

Associated Unified Control ID

Associated Framework Control

CTRL-349

REQ-26, REQ-27

Did this answer your question?