Password Policy and Best Practices

This policy establishes a standard for the creation of strong passwords, the storage and protection of those passwords, and the frequency of change. The scope of this policy includes all individuals who have access to, or are responsible for an account, with any form of access requiring a password on any managed system or network, and residing at any facility used by Collabrance, or any of MSPs working with us.

Requirements

  • All user accounts must have a password
  • Passwords must:
    • Be a minimum length of nine (9) characters on all systems
    • Be changed every 90 days at a minimum
    • Lockout the user after 7 failed attempts
    • Meet complexity requirements (3 of the 4: upper case, lower case, number, special characters)
  • Collabrance and Dealers should have their own administrative accounts for each domain with passwords that are not shared

General Policy

  • Consideration should be made to change all system-level passwords (e.g., svcremoteadmin, admin, root, enable, etc.) at least every 90 days.
  • All user-level passwords for any systems, networks or services (eg., Hosted E-Mail, website access, desktop computer both domain and local access, etc.) should be changed at least every 90 days and should not be repeated regularly.
  • User accounts with access to elevated privileges should have unique passwords. The password should be different from all other accounts held by the user.
  • Passwords must not be inserted into email messages, or other forms of electronic communication.

Best Practices

Password Creation Recommendations

Password or Account Removal

Password and Account Protection

Remote Access Users

** Disclaimer: Service Providers must comply with identified Collabrance Requirements in order for items referenced in our Service Catalog to perform properly. **