Skip to main content

Password Protection Policy

Passwords are an important aspect of computer security.  A poorly chosen password may result in unauthorized access and/or exploitation of our resources.  All staff, including contractors and vendors with access to <Company Name> systems, are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.

 

The purpose of this policy is to establish a standard for creation of strong passwords and the protection of those passwords.

 

The scope of this policy includes all personnel who have or are responsible for an account (or any form of access that supports or requires a password) on any system that resides at any <Company Name> facility, has access to the <Company Name> network, or stores any non-public <Company Name> information.

 

 

 

Application developers must ensure that their programs contain the following security precautions:

Applications must support authentication of individual users, not groups.

Applications must not store passwords in clear text or in any easily reversible form.

Applications must not transmit passwords in clear text over the network.

Applications must provide for some sort of role management, such that one user can take over the functions of another without having to know the other's password.

 

Compliance Measurement

The Precision Computer team will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and feedback to the policy owner.

Any exception to the policy must be approved by the Precision Computer Team in advance.

An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.

Password Construction Guidelines