Back

Password Standard v1 approved by NCPSB JAN 23

Password Standard  v1 approved by NCPSB JAN 23

Password Standard v1 approved by NCPSB JAN 23

Status: Live
Published: 26/01/2023
Security level: Official
Amended / Internally developed: No
Live on platform: 16/03/23
Retired on platform:
Target Audience: Business / General
Authoring body: Police Digital Service
Grading:
Standards
Abstract

This standard supports the National Community System Policy System Access requirements with respect to defining requirements for the use and selection of a password / passphrase-based method of authentication. It should be read in conjunction with the System Access standard. Passwords represent only one method of authentication (something that you know) and should be combined with other methods such as something you have (token) or something you are (biometric). It is not always possible especially with legacy applications or services to utilise multi-factor authentication, and this is where this standard can help to ensure that risks are effectively managed. A strong passphrase / password will help to ensure lawful business access to applications, mobile devices, systems and networks when combined with an agreed access control policy and supported by an Identity and Access Management (IAM) system. Undertaking a business impact assessment (BIA) is important to determine specific information security requirements to support proportionate risk management. This Standard is aligned with the NCSC’s password guidance.

Category: Security