Password Protection Policy
Password Protection Policy
Free Use Disclaimer: This policy was created by or for the SANS Institute for the Internet community. All or parts of this policy can be freely used for
your organization. There is no prior approval required. If you would like to contribute a new policy or updated version of this policy, please send email to
[email protected].
1. Overview
Passwords are a critical aspect of computer security. A weak or compromised
password can result in unauthorized access to our most sensitive data and/or
exploitation of our resources. All staff, including contractors and vendors with
access to <Company Name> systems, are responsible for taking the appropriate
steps, as outlined below, to select and secure their passwords.
2. Purpose
The purpose of this policy is to establish a standard for the secure use and protection of all
work related passwords.
3. Scope
The scope of this policy includes all personnel who have or are responsible for an account
(or any form of access that supports or requires a password) on any system that resides at
any <Company Name> facility, has access to the <Company Name> network, or stores any
non-public <Company Name> information.
4. Policy
5. Policy Compliance
7. Revision History
October, 2017 SANS Policy Updated to confirm with new NIST SP800-
Team 63.3 standards.