The policy that no one maintains is not a policy. That's where most rules break down.
Workable password policies revolve around three things: a password manager so no one has to remember, two-factor authentication on anything that gives access to money or data, and a set procedure for when someone leaves. Mandatory monthly changes are counterproductive.
STEP BY STEP
This is how you approach it
- Get a password managerThat is the only measure that makes unique and strong simultaneously possible. Without a manager, everyone reuses passwords, no matter how strict your policy is.
- Turn on two-factor on what mattersEmail first, then domain, hosting, accounting and banking. Email first, because that resets everything else.
- Do not share accounts, but provide your own accessOne shared login that everyone can access means you never know who did what and leaving is always a problem.
- Create an out-of-service procedureWhat access should be revoked when someone leaves. Write that down once; during a departure, figuring it out is the problem.
- Allow long sentences instead of artificeA long plain sentence is more secure than a short password full of characters, and easier to remember for the few you need to know by heart.
- Stop making mandatory periodic changesThis leads to predictable variants with a number behind them. If you suspect a leak, do not change according to a calendar.
PITFALLS
Which is counterproductive
Rules that are too strict are circumvented. Mandatory changes every month result in passwords with an increasing number behind them, which is weaker than one strong password that remains.
And a shared account for convenience. That is the most common reason that a departed employee still has access months later.
- No mandatory monthly change — produces predictable variants.
- No shared accounts — no one knows who did what.
- A password manager — the only workable solution.
- Two-factor on email — the most important of them all.
- There is an exit procedure — write it down once.
- Allow long sentences — safer and more memorable.
FREQUENTLY ASKED QUESTIONS
More about access
Which password manager?
There are several good options, including open source variants that you can host yourself. More important than the choice is that everyone uses the same one, otherwise islands will form again.
What if someone suddenly disappears?
Therefore, access should never be up to one person. Make sure that at least two people have access to the critical accounts, and record who they are.
Will you arrange this?
We ensure that the accounts we manage are in good condition and that there is more than one administrator. We think along with you for your broader company policy, but that is not a service from us.
CONTINUE READING
Of course, continue reading about this subject.
Access in order?
We look at which accounts are critical and where your security first falls short.