Skip to main content
Guidance

Password administration for system owners

Password strategies that can help your organisation remain secure.

Page 2 of 3

Password policy: updating your approach

Advice for system owners responsible for determining password policies and identity management within their organisations.

Password policy: contains advice for system owners responsible for determining password policy. It may be useful also for anyone developing or maintaining these services used by organisations.

The NCSC is working to reduce organisations' reliance on their users having to recall large numbers of complex passwords. This guidance advocates a greater reliance on technical defences and organisational processes, with passwords forming just one part of your wider access control and identity management approach.

More specifically, this guidance will help you to:

  • understand the benefits and limitations of passwords
  • examine and (if necessary) challenge existing corporate password policies, and help update to a modern approach
  • understand the decisions to be made when determining password policy
  • learn how technical measures can reduce the password burden on your users
  • implement password policies which support the ways in which people naturally work
  • help users to create and manage passwords that are harder to guess

As a system owner, you may not be directly responsible for the authentication methods within third party services your organisation uses. In these cases, this guidance can help you to understand the risks and benefits when selecting such services, and inform your selection of one that best meets your business and security needs.



In summary:

  • Only use passwords where they are needed and appropriate
  • Consider alternatives to passwords such as SSO, hardware tokens and biometric solutions.
  • Use MFA where possible for all important accounts and internet facing systems.

In summary:

  • Use account lockout or throttling to defend against brute force attacks.
  • If using lockout, allow users between 5 and 10 login attempts before locking out accounts.
  • Consider using security monitoring to defend against brute force attacks.
  • Password blacklisting prevents common, guessable passwords being used.




Reviewed

Version

1.0