accessVersion 1SOC2ISO27001NIST800-171
Password Policy
Authentication requirements aligned with NIST SP 800-63B, including MFA.
Download PDFSHA-256 07ba86829bf878e2…
Password Policy
Aligned with NIST SP 800-63B digital identity guidelines.
1. Requirements
- Minimum length: 14 characters for human passwords.
- No composition rules (no forced mix of symbols/numbers). Entropy beats predictable complexity.
- Passphrases encouraged: 4+ random words from a diceware list are acceptable and often stronger than random strings.
- No forced periodic rotation. Rotate only on suspicion of compromise, on role change, or on separation.
- Breach-list screening: new passwords are checked against known compromised password corpora (e.g., HIBP k-anon API) at set-time. Matches are rejected.
- No reuse across Rex Black systems. Personnel should use the Rex Black Vault to generate unique credentials per site.
2. Multi-factor authentication
- MFA is required on every
@rexblack.comaccount and every admin surface. - Accepted factors (in order of preference):
- Platform authenticators (Touch ID / Windows Hello / Face ID).
- Hardware security keys (WebAuthn / FIDO2, e.g., YubiKey).
- TOTP authenticator apps.
- SMS, prohibited except as a break-glass fallback recorded in the runbook.
- Every user maintains at least 2 MFA methods on critical accounts (Google Workspace, AWS, GitHub) so losing one does not lock them out.
3. Storage
- Personnel store their passwords in the Rex Black Vault or an approved password manager.
- Plaintext passwords are never written to text files, emails, Slack messages, or tickets. If a shared credential must be handed off, it is shared through the Vault's per-user share flow.
4. Break-glass accounts
- Two sealed-envelope break-glass accounts exist:
- AWS root.
- GitHub organization owner.
- Credentials are stored by the CEO in a physical safe and mirrored to legal counsel. Opening an envelope triggers an incident and immediate rotation after use.
5. Enforcement & exceptions
- Password policy is enforced by identity providers (Google Workspace, NextAuth, AWS IAM).
- Exceptions require Security Officer written approval and a compensating control.
6. References
002-access-control-policy.md008-cryptography-and-key-management-policy.md
7. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.