Passwords are an important aspect of computer security. They are the front line of protection for online and offline accounts and devices. A poorly chosen password may result in the entire Flinkā operations being compromised. As such, all Flink Employees (including trainees) and Contractors are responsible for taking the appropriate steps, as outlined below, to select, change and secure their passwords.
Purpose & Scope
The purpose of this policy is to establish a standard for the creation of strong passwords, the protection of those passwords, and the frequency of change.
The scope of this policy includes all personnel who have or are responsible for an account (or any form of access that supports or requires a password) on any system that is used for Flinkā business activities.
General
In choosing passwords, the following rules shall be followed:
Googleās Single Sign-On feature must be used, where available.
Where Single Sign-On is not available, the combination of a strong password and multi-factor authentication systems must be used.
Where multi-factor authentication systems are not available, a strong password must be used.
Except when using Googleās Single Sign-On feature, different passwords must be used for different services.
Except for cases where its use is technically impossible, the use of a safe password manager tool is mandatory.
Passwords of services not employing multi-factor authentication systems or Googleās Single Sign-On must be changed every year.
Compromised passwords are to be changed immediately.
Shared passwords should only be used in unique situations when there is no other alternative. They must be part of the Information Security administered global password management database.
Passwords must not be inserted into email messages or other forms of electronic communication.
āGuidelines for Password Construction
Passwords must:
Have a minimum length of Eight (8) characters on all systems.
Unless this is technically impossible, passwords must contain a combination of upper and lower case alphabetic, numeric, and special characters.
Not be the same as the User ID.
Not be identical to the previous ten (10) passwords.
Not be transmitted in clear or plain text.
āGuidelines for Password Reset
Administrators of Flinkā services must always ensure that passwords are only reset for authorized users.
ā
ā
Password Protection Standards
Do not share Flinkā passwords with anyone, including administrative assistants or secretaries. All passwords are to be treated as sensitive Flink information.
Here is a list of āDOs and DONāTsā:
Do not reveal a password over the phone to anyone.
Do not reveal a password in an email message.
Do not reveal a password to the boss.
Do not talk about a password in front of others.
Do not hint at the format of a password (e.g., āmy family nameā).
Do not reveal a password on questionnaires or forms.
Do not share a password with family members.
Do not reveal a password to a co-worker while on holiday.
Do not use the "Remember Password" feature of applications.
Do not write passwords down and store them anywhere in your office.
Do not store passwords in an unencrypted file on ANY computer system.
Do not ask for anyoneās password.
If someone demands a password, refer them to this document or have them call the current ISO.
If an account or password is suspected to have been compromised, report the incident to the ISO and change all passwords.
Make sure your passwords are masked or suppressed on all online screens and are never printed or included in reports or logs.
Enforcement
Flink takes security very seriously to protect our users, assets and data. Flink could take appropriate actions in case of violating the company policy.