A.1 Password Standards

Version: April 2025
Aligned with: ISO/IEC 27001:2022 (Annex A: A.5.17, A.8.5)
Applies to: All employees, contractors, and system administrators

Purpose
To establish minimum password security requirements that protect organizational accounts and systems from unauthorized access.

1. Password Complexity Requirements
(Aligned with A.5.17 – Authentication information)

  • Minimum 12 characters in length
  • Must contain at least three of the following: uppercase letters, lowercase letters, numbers, special characters
  • Cannot contain dictionary words or personal information
  • Must be unique and not reused for the last 12 passwords

2. Password Management
(Aligned with A.8.5 – Secure authentication)

  • Passwords must be changed every 90 days for privileged accounts
  • Use of approved password managers is encouraged
  • Multi-factor authentication required for all administrative accounts
  • Default passwords must be changed immediately upon system deployment
Direct URL: