Short answer: A modern password policy should favour sufficient length, blocked compromised passwords, MFA where appropriate, secure storage and recovery, and changes after suspected compromise—not arbitrary complexity rules or routine forced rotation.
Credential misuse remains a common attack vector across organizations of all sizes. A Password Policy should directly address predictable weaknesses while remaining operationally realistic.
Overly complex rules create workarounds. Insufficient rules create exposure.
The policy must balance both.
What to Include
1. Minimum Length Requirements
Length has greater security impact than excessive character variety.
Define:
-
Length requirements that reflect the authentication design. Current NIST guidance specifies at least 15 characters for passwords used as a single factor and at least eight when the password is used only as part of MFA.
-
Encouragement of passphrases where feasible
Clarity matters more than complexity formulas.
2. Multi-Factor Authentication (MFA)
Passwords alone are insufficient for higher-risk access.
Specify:
-
Mandatory MFA for administrative accounts
-
MFA for remote access (VPN, cloud platforms)
-
MFA for systems containing sensitive or regulated data
The policy should clearly define where MFA is required, not suggest it optionally.
3. Prohibited Practices
Explicitly state what is not allowed:
-
Sharing credentials
-
Reusing corporate passwords across external services
-
Storing passwords in unsecured files or notes
-
Using default vendor passwords
Prohibitions remove ambiguity.
4. Secure Storage Guidance
Encourage:
-
Approved password managers
-
Encrypted storage mechanisms
-
Unique passwords per system
If a password manager is mandated, identify the approved solution.
5. Compromise Response Procedure
Define steps when exposure is suspected:
-
Immediate password reset
-
Session invalidation where applicable
-
Notification to IT or security
-
Review of account activity
Response clarity limits dwell time after compromise.
6. Rotation Rules Based on Risk
Avoid arbitrary timelines.
Instead:
-
Require a change when there is evidence of compromise
-
Avoid routine forced changes unless another applicable requirement or a specific risk decision justifies them
-
Document exceptions where legacy systems or contractual requirements impose different rules
Unnecessary forced changes often degrade password quality.
What to Avoid
Excessive Complexity Requirements
Rules such as mandatory special characters in fixed positions often produce predictable patterns. Complexity without usability reduces security.
Frequent Mandatory Rotation Without Cause
Current NIST guidance says verifiers should not require periodic password changes and should require a change when there is evidence of compromise.
Vague Language
Statements like “use strong passwords” provide no operational instruction. Policies must be specific and measurable.
Unrealistic Enforcement
If employees cannot comply easily, they will bypass controls. Policies must reflect actual system capabilities and workflow realities.
Structural Objective
An effective Password Policy should:
-
Be concise
-
Define measurable requirements
-
Align with authentication risk levels
-
Integrate MFA as a primary control
-
Remain enforceable through technical configuration
Security strength is determined by adoption and enforcement, not document length.
Sources and further reading
Related Aneo resources
- How to build your first security policy set as a growing business
- How to generate customised security policies
A practical next step
Use this guidance as a starting point, then check it against the way your business actually operates. Security policies should be reviewed, approved, implemented, and supported by evidence.
Aneo Framework Pro uses questionnaire answers and business context to generate tailored, editable security policy drafts. Its outputs support review and readiness work; they do not certify a business, replace implementation, provide legal advice, or remove the need for human review.
