AUTH-11 Password Configurations

Estimated reading: 2 minutes 1815 views

What is AUTH-11 Password Configurations Control?

Password Configurations are an important part of the Logical Access process. A password policy is a configuration of a set of attributes that an administrator defines from the documented policy and implements on all organizational resources. Creating strong password requirements will help mitigate the risk of unauthorized access. It is recommended to remain updated on password best practices as they tend to change.

Available tools in the marketplace 

Tools
 No tool recommendation is made for this section.

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version:

Control implementation

Note: This control is automated by TrustCloud. Connect your system to enjoy the benefits of automation.

To implement this control manually, 

  1. Document a password policy that defines what the password requirements are (min length, max length, characters, etc.). Use NIST for guidance.
  2. Enforce the defined configurations on all systems.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below suggested action:

  1. Provide the password policy that shows the required password configurations.
  2. Provide a screenshot of the password configuration settings for each system.

Evidence example

From the suggested action above, an example is provided below.

  1. Provide the password policy that shows the required password configurations.
    Refer to the template for an example.
  2. Provide a screenshot of the password configuration settings for each system.
    The following screenshot shows the password configurations. Provide a similar artifact for the relevant system.
    Google search
    AUTH 11 Password Configurations 01

Join the conversation

You might also be interested in

Documentation Templates

Documentation Templates are documents that provide a content outline to meet certain documentation needs....

Backup policy template – Download for free

The Data Backup Plan template helps you document in detail the data backup needs...

HR-13 Employee Handbook/Code of Conduct

HR-13 Employee Handbook or Code of Conduct communicates the organization’s values and ethics. It...

AUTH-1 Single Sign On (SSO)

Single Sign On (SSO) Control is a best practice recommendation for critical systems....

Security Incident Report Template

The Security Incident Report template helps you document the steps used to assess and...

BIZOPS-6 Disaster Recovery Testing

BIZOPS-6 Disaster Recovery Testing control refers to the exercise of identifying the critical systems...

PDP-10 SDLC – Separation of environments

PDP-10 SDLC Separation of Environments is important to maintain separate environments to develop, test,...

Privacy Committee Charter Template

Privacy Committee Charter serves as a foundational document, establishing the framework for the committee's...
ON THIS PAGE
SHARE THIS PAGE

SUBSCRIBE
FlightSchool
OR