Nested Knowledge

Bringing Systematic Review to Life

User Tools

Site Tools


wiki:policies:password

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
wiki:policies:password [2023/10/06 21:41]
katcow
wiki:policies:password [2024/01/31 18:42] (current)
katcow
Line 15: Line 15:
 ===== Policy ===== ===== Policy =====
  
-====    Internal Company Passwords     ====+==== Internal Company Passwords ====
  
-  * +**Application Passwords** - All programs, including applications developed internally by Nested Knowledge must be password protected.
- +
-**Application Passwords**  - All programs, including applications developed internally by Nested Knowledge must be password protected. +
-  *+
  
 **Changing Passwords **- All passwords must be promptly changed if they are suspected of being disclosed, or known to have been disclosed to unauthorized parties. **Changing Passwords **- All passwords must be promptly changed if they are suspected of being disclosed, or known to have been disclosed to unauthorized parties.
-  * 
  
-**Sharing Passwords**  - Passwords must be kept confidential and may not be shared among users. Users are prohibited from recording passwords in an unencrypted medium, like a notetaking application, mobile phone, or piece of paper. +**Sharing Passwords** - Passwords must be kept confidential and may not be shared among users. Users are prohibited from recording passwords in an unencrypted medium, like a notetaking application, mobile phone, or piece of paper. Company credentials, including work email and other work accounts, may NEVER be used on personal websites.
-  *+
  
-**Password Storage -**  Passwords will not be stored in readable form without access control or in other locations where unauthorized persons might discover them. All such passwords are to be strictly controlled using either physical security or computer security controls +**Password Storage -** Passwords will not be stored in readable form without access control or in other locations where unauthorized persons might discover them. All such passwords are to be strictly controlled using either physical security or computer security controls 
-=== Password Complexity ===+==== Password Complexity ====
  
 Passwords must: Passwords must:
Line 41: Line 36:
   * must not match your user name or email   * must not match your user name or email
  
-** <font 20px/inherit;;inherit;;inherit>Application Passwords</font> **+=====    Application Passwords    =====
  
-**Application Passwords** - All programs, including third party purchased software and applications developed internally by Nested Knowledge must be password protected.+**Application Passwords**  - All programs, including third party purchased software and applications developed internally by Nested Knowledge must be password protected.
  
 === User Authentication === === User Authentication ===
  
 All systems will require a valid user ID and password. All unnecessary operating system or application user IDs not assigned to an individual user will be deleted or disabled. The use of a four digit pin or secret questions is not acceptable as an authentication method. All systems will require a valid user ID and password. All unnecessary operating system or application user IDs not assigned to an individual user will be deleted or disabled. The use of a four digit pin or secret questions is not acceptable as an authentication method.
 +
 +As described in our [[:wiki:policies:dev|Secure Development Policy]], Nested Knowledge does not manage user passwords or authentication (handled by [[https://auth0.com/|Auth0]] and Auth0 Lock). All communications with Auth0 from the client are encrypted (TSL), ensuring passwords are not communicated in plain text. Passwords stored by Auth0 are similarly salted & encrypted (bcrypt). Communications relayed by the client are similarly encrypted & RSA signed.
  
 === Choosing Passwords === === Choosing Passwords ===
wiki/policies/password.1696628519.txt.gz · Last modified: 2023/10/06 21:41 by katcow