Rules governing password creation, use, and management across the organisation.
Password policies define requirements for password creation and management—minimum length, complexity requirements, expiration periods, and reuse restrictions. Modern guidance (NCSC, NIST) favours longer passwords/passphrases over complexity, discourages forced regular changes, and emphasises checking against known breached passwords. Password policies should encourage password manager use and support transition to MFA and passwordless authentication.
Why It Matters
The DSC Perspective:
Outdated password policies (frequent changes, complexity rules) often reduce security by encouraging predictable patterns. Follow modern guidance—length over complexity, MFA over rotation, and password managers for unique passwords.
