Password policy
Password Policy
Strong password practices are essential for protecting user accounts and ensuring information security.
Creating a Strong Password
When creating a password, please consider the following:
-
Your password must not be easy to guess. Do not use personal or easily accessible information such as your name, surname, date of birth, phone number, or institution name.
-
Avoid commonly used and easily guessed passwords such as
123456,password, orqwerty. -
Comply with the minimum password length and security requirements defined by the institution.
-
Use long and difficult-to-guess passwords whenever possible.
-
The use of letters, numbers, and special characters is recommended. However, password security depends not only on character complexity but also on having a sufficiently long and difficult-to-guess password.
Password Usage
-
Do not use the same password for multiple systems or services.
-
Avoid reusing previously used passwords.
-
Default or temporary passwords provided by a system must be changed upon first use.
-
Passwords must not be shared with other individuals.
-
Do not store passwords in emails, messages, on paper, or in unencrypted plain-text files.
-
If you suspect that your password has been disclosed or compromised, change it immediately.
Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) should be enabled on systems that support it.
For critical systems and services, authentication should not rely solely on passwords where an additional authentication method is available.
Information Security
Passwords must be stored and transmitted using secure methods. Storing or transmitting passwords in plain text is not permitted.
Remember: A strong password is one of the most important steps in protecting your account. Keep your password confidential, do not reuse it across different systems, and change it immediately if you suspect that it has been compromised.
Alignment with ISO/IEC 27001
Password security is particularly associated with the following controls under ISO/IEC 27001:2022:
-
Annex A 5.17 – Authentication Information
-
Annex A 8.5 – Secure Authentication
ISO/IEC 27001:2022 does not mandate a specific password length (such as 12 characters). Organizations are expected to establish and implement appropriate password security requirements based on their risk assessment. ISO/IEC 27002:2022 provides additional guidance on the implementation of these controls.