Password Policy

1. INTRODUCTION

1.1 This policy supports the Digital Services Cyber Essentials certification principles to ensure that passwords used to access computer resources are selected, maintained, and updated in line with the Post Op security profile standards.

1.2 Password policies are used to mitigate possible attacks against the Post Op network infrastructure and the data held within it. Use of sufficiently long passwords, multi-factor authentication, and blocking of known weak or breached passwords helps mitigate attacks that attempt to guess passwords. Regularly forcing password changes does not provide additional protection against this risk and is not required by this policy; a password is instead changed when there is evidence or suspicion that it has been compromised.

1.3 This policy therefore aims to provide a policy and guidance on password structure, technical standards and technology required to keep the Post Op IT network secure and confidential.

2. PASSWORD SELECTION

To protect Post Op systems and data, users must select a password that is secure and difficult to guess. In accordance with current security best practice the following rules are mandatory:

2.1 All passwords should have a minimum of twelve characters (a minimum of eight characters is acceptable only where multi-factor authentication is enforced on the account).

2.2 There is no mandatory character-set combination; passwords are not required to mix uppercase, lowercase, numbers and symbols. Users may use long, memorable passwords such as three random unrelated words.

2.3 All passwords will be checked against a blocklist of common, default, or previously breached passwords at the point of creation and rejected if found.

2.4 Previous passwords used for a Post Op system must not be re-used.

2.5 In addition, while not actively enforced by the password creation process, accounts created for use on external online resources must not use the same password as used for Post Op authentication. Passwords must not be something that can easily be guessed (avoid using your name, children or a pet's name, car registration number, football team, etc.). Password maximum length is not limited by policy and is determined by user preference. Multi-factor authentication (MFA) must be enabled on all accounts and cloud services that support it, and is mandatory on all administrative accounts.

2.6 This policy covers the password requirements for all systems and applications used within the Post Op environment including third-party externally hosted applications. The password policy will be reviewed every 12 months to ensure that the security settings remain relevant and applicable to technologies, applications and services utilised by Post Op.

3. CHANGING A PASSWORD

3.1 Passwords are not required to be changed on a regular fixed schedule, as doing so does not mitigate long-term exploitation of a disclosed or discovered password. A password must instead be changed where there is evidence or suspicion that it has been compromised, following a confirmed security breach, on a user's role change, or on leaver offboarding.

3.2 Passwords are the mechanism used to protect the security of Post Op systems and must be protected.

  • Passwords must be kept secret
  • Passwords must not be written in a form that others could identify
  • Passwords must not be stored electronically in a non-encrypted format
  • Passwords may be stored in password management applications where appropriate
  • Passwords must never be shared with others
  • Care should be taken to prevent anyone from watching you type your password
  • Devices should not be left unattended and unlocked in public spaces or communal areas
  • Multi-factor authentication must be enabled on all accounts and cloud services that support it, and is mandatory on all administrative accounts

3.3 To keep up to date with best practice authentication and password management policies, the Post Op user password policy will adhere to the following conditions:

  • First time or temporarily reset passwords will be a randomly generated, single-use password that is 12 characters long. The user will be required to change the password upon first logon.
  • Passwords must be a minimum of 12 characters in length (8 characters where MFA is enforced).
  • Passwords are not required to follow a fixed complexity pattern, but must be checked against a blocklist of common or breached passwords. Post Op advises that users choose passwords of at least 12 characters, such as a memorable combination of three random unrelated words, rather than relying on complex character substitutions.
  • Passwords are not set to expire on a fixed schedule. Passwords remain valid indefinitely provided they meet the requirements set out in this policy and there is no evidence or suspicion of compromise.

The policy and recommendations are in line with the guidance given by The National Cyber Security Centre.