Password Policy
What is Password Policy?
A set of rules designed to enhance computer security by encouraging users to create strong passwords and manage them properly. Password policies define minimum length, complexity, rotation frequency, and history requirements.
Terms that appear alongside password policy
Each of these is named in at least one of the same controls as password policy. The number is how many controls name both.
- policy 9 shared controls
- authentication 5 shared controls
- multi factor authentication 4 shared controls
- least privilege 2 shared controls
- privileged access management 2 shared controls
- remote access 2 shared controls
- access management 2 shared controls
Frameworks that govern password policy
What the standards actually require on password policy
Requirements naming password policy across 6 standards, quoted from the control text.
Enforce a password policy that requires sufficient length, complexity, history, and rotation, and apply it consistently across all accounts that touch SWIFT components.
CSCF-4.1 · Password Policy →Keep an approved password policy that sets strength requirements, implement it in the systems it governs, and review it at least annually.
CCM-IAM-02 · Strong Password Policy and Procedures →Authentication must be protected against brute force, including minimum password length, password deny lists or use of MFA and lockout or throttling.
CEP-UA-03 · Password Policy and Brute Force Protection →Protect credentials, especially highly privileged accounts: implement multi-factor authentication where possible, reduce privileges to least necessary, enforce secure password policy (length over complexity), ensure unique credentials for all accounts includin...
CISA-ICS-7S-5 · Manage Authentication →UR E26 Goal 2 (Protect) requires access control + authentication + authorization mechanisms for all CBS. Unique user identification (no shared accounts where feasible); strong password policy (per NIST SP 800-63B + IEC 62443 + ship operational reality);
IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles · IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management →Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...
MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot →Questions people ask about password policy
What is Password Policy?
Why is Password Policy important for compliance?
Which compliance frameworks address Password Policy?
Where can I learn more about Password Policy?
See how Password Policy applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.