Password & Access Policy — Template

Short on purpose — policies people read beat policies that impress auditors.
Organisation: [Name] · Approved by: [Name, role] · Review: [annually]

1. Passphrases, not passwords

2. Use the password manager

3. Multi-factor authentication (MFA)

4. Sharing and leaving

5. Admin accounts

6. If a password may be exposed

Change it immediately, tell [contact], and check for unfamiliar logins or email rules. No blame for reporting — ever.