Skip to main content

Password management

Create and enforce password policies to keep data and systems secure.

Actions

Install a password policy. Make sure that it aligns with the national standards[External]. 

Implement password management tools to help employees securely manage multiple accounts and passwords. 

Risk factors

Compromised passwords are a common entry point for cyber criminals.  A weak password may:

  • Result in unauthorized access to an organization’s systems and data
  • Provide attackers with an entry point to install malicious software such as ransomware

Employees who use easy to guess passwords put the organization at increased risk. 

Using the same passwords for all your accounts is a very risky practice. It should be strongly discouraged.

Recommendations

  • Implement a password policy that favors length over complexity
  • Encourage employees to use long passphrases (14 characters or more) instead of passwords
  • Install multi-factor authentication whenever possible
  • Ensure employee:
    • Do not reuse the same passwords for multiple accounts
    • Change their password immediately if they suspect an account is compromised
  • Consider purchasing a password management tool for employees

Related

Page last updated on February 6, 2025.