Password Policy¶
password Policy
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Apr/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Purpose¶
The purpose of this Policy is to define the rules and guidelines for the password management mechanism within the organization. The purpose of this procedure is to implement the password management mechanism in accordance with the Password Policy.
Scope¶
The scope of this policy includes all personnel who have or are responsible for an account (or any form of access that supports or requires a password) on any system and supporting facilities of the organization.
This procedure is applicable to all users who create and use passwords to access tecciance Information and IT assets.
Responsibilities¶
The primary ownership of implementing this Policy lies with the IT Department Head. The ISMS Head shall implement this Procedure under the guidance of the Leadership Team and in coordination with Department Heads.
Policy¶
There shall be a formal Procedure for Password Management in tecciance, which shall be strictly adhered to by all users of information and IT assets of tecciance.
This procedure shall be system- controlled, wherever technically possible. IT shall develop and implement administrative procedures to create, change, reset, and subsequently communicate initial passwords to the concerned users.
Wherever technically feasible, a control shall be enforced to change the temporary password at the first logon by the concerned user.
The System Administrator shall ensure changing all default passwords provided by Vendors. Passwords shall not be stored on computer systems in an unprotected form.
The use of a password by more than one user (Sharing of passwords) is discouraged in tecciance. However, sharing passwords for a legitimate business reason shall be allowed after appropriate authorization received from Head – IT Function. The use of Group user-id/password shall be limited to situations dictated by operational necessity and/or under certain circumstances approved by Head – IT Function.
All systems and applications shall adhere to the password policy.
Procedure¶
Passwords used shall be a minimum of 8 characters. Password and User ID shall not be identical. A password shall be different from the previous three (3) passwords.
Password Modification Procedure:¶
Users shall modify/change their passwords using the password change option provided with the system, following the password guidelines.
Password Reset Procedure:¶
-
If a user is unable to recall his/her current password, then he/she will initiate a request to reset the password through email/phone or notification.
-
The IT Department will reset the password to the predefined default password and enable the setting for prompting the user to change the password at first log-on.
-
The records of password reset shall be maintained.
Password Protection Guidelines:¶
-
Passwords set during the user creation process must be changed at the first Logon. This applies to all user-ids and E-mail ids.
-
The use of a single password shall be avoided to access various tecciance’s information/IT systems (Ex. Active Directory Systems). Details in relation to User ID & password etc. should not be sent using clear text across systems/SMS.
-
Passwords shall not be revealed to anyone orally in person/phone/mobile sets or through fax/Internet messenger services.
-
Passwords shall be encrypted when stored in files or databases or transmitted over the Internet, public networks, or wireless devices. Where encryption is not possible, access to such files/databases shall be restricted. The format of a password shall not be revealed without authorization.
-
Passwords shall not be revealed on questionnaires or security forms.
-
Passwords shall not be shared with family members and co-workers. The "Remember password" feature of applications shall not be used. Passwords shall not be written down and stored anywhere inside and outside the Organization.
-
Users shall log out when leaving their desk for extended periods. Especially administrative users with extended rights. If an account or password is compromised, the password must be changed immediately.
Protection of Super user Password/Administrator Password¶
-
All superuser/administrator passwords of critical servers & critical devices should be sealed in an envelope and kept in lock & key with Head-IT. This will aid in retrieving the administrator password if forgotten or if the concerned person has left without surrendering passwords. In case the password needs to be retrieved from a sealed envelope, it should be changed.
-
Immediately, and a new sealed envelope shall be kept with Head-IT as per Sealed hard copy of administrative password.
-
In case a person holding administrator/superuser password resigns, the password should be changed immediately and stored in a new sealed envelope and kept with Head-IT.
In case of separation of an employee¶
-
Passwords for all accounts and the user ID must be changed on separation/resignation of employees from the IT Function. For another category of employees, the relevant accounts must be disabled/removed.
-
If the user ID is required after the separation of an employee, the concerned Function Head should request keeping the ID live and changing the password.
-
The Function Head should also inform who needs to have the new password.
User Responsibilities¶
Do’s:¶
ALWAYS USE passwords of the following types:¶
-
Contain both upper- and lower-case characters (e.g., a-z, A-Z) Are at least eight characters long.
-
Passwords that can be easily remembered. One way to do this is to create a password based on a song title, affirmation, or other phrase. For example, the phrase might be: "This May Be One Way to Remember" and the password could be: "TmB1w2R!" or "Tmb1W>r~" or some other variation. Use English spellings for words/songs in your native language.
Don’ts:¶
DO NOT USE the following types of passwords:¶
-
Passwords based on personal information, names of family members, etc.
-
Password, which is a word in any language, slang, dialect, jargon, or found in a dictionary. Never write down passwords or store them online.
-
Password containing less than seven characters.
-
Never use a password that is a commonly used word such as names of family members, pets, friends, co-workers, fantasy characters, etc.
-
Computer terms and names, commands, sites, companies, hardware, software.
-
Birthdays and other personal information such as extensions or phone numbers. Word or number patterns like aaabbb, gfedcba, 123321, etc.
-
Do not use either of these examples as passwords.
Terms & Definitions¶
-
ISMS: Information Security Management System
-
LT: Leadership Team
-
ISG Head: Person/Team heading the ISMS Activities
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
SSO and phishing-resistant MFA are preferred over password-only access for interactive users. Service accounts shall not use shared interactive passwords.