Password Policy
Password Policy
01/06/2024)
1. Purpose
The purpose of this policy is to establish a standard for the creation, management, and use
of SSOID passwords on the RajSSO platform and to protect against incidents of Identity
Theft arising due to weak SSOID passwords defined by end-users. This policy aims to ensure
that SSOID passwords are strong & regularly changed/updated by end-users.
2. Scope
The Scope of this policy includes all the SSOIDs created on the RajSSO Platform.
3. Policy
3.1. Password Creation
3.1.1 Length and Complexity: Passwords must be at least 8 characters long (max. 30
characters) and include a mix of uppercase letters + lowercase letters + digits + special
characters.
3.1.2 Prohibited Passwords: End-users of SSOID to avoid common words, phrases, or easily
guessable information such as mobile number, city of birth, DOB, common names etc.
3.1.3 The password shall not be a derivative of the SSOID.
3.1.4 The password shall not be a slang, dialect, jargon etc.
3.1.5 The password shall not be a common usage word such as names of family, pets,
friends, co-workers, fantasy characters, etc
3.1.6 The password shall not be based on computer terms and names, commands, sites,
companies, hardware, or software.
3.1.7 The password shall not be based on birthdays and other personal information such as
addresses and phone numbers.
3.1.8 The password shall not be a word or number pattern like aaabbb, qwerty, zyxwvuts,
123321, etc., or any of the above spelled backward.
3.1.9 Uniqueness: Passwords must be unique and not used for any other accounts,
especially external services or websites.
5. Policy Review
5.1 This policy will be reviewed half-yearly and updated as needed to ensure compliance
with security best practices and evolving threats.