Skip to main content

accessVersion 1SOC2ISO27001NIST800-171

Password Policy

Authentication requirements aligned with NIST SP 800-63B, including MFA.

Download PDFSHA-256 07ba86829bf878e2…

Password Policy

Aligned with NIST SP 800-63B digital identity guidelines.

1. Requirements

  1. Minimum length: 14 characters for human passwords.
  2. No composition rules (no forced mix of symbols/numbers). Entropy beats predictable complexity.
  3. Passphrases encouraged: 4+ random words from a diceware list are acceptable and often stronger than random strings.
  4. No forced periodic rotation. Rotate only on suspicion of compromise, on role change, or on separation.
  5. Breach-list screening: new passwords are checked against known compromised password corpora (e.g., HIBP k-anon API) at set-time. Matches are rejected.
  6. No reuse across Rex Black systems. Personnel should use the Rex Black Vault to generate unique credentials per site.

2. Multi-factor authentication

  1. MFA is required on every @rexblack.com account and every admin surface.
  2. Accepted factors (in order of preference):
    • Platform authenticators (Touch ID / Windows Hello / Face ID).
    • Hardware security keys (WebAuthn / FIDO2, e.g., YubiKey).
    • TOTP authenticator apps.
    • SMS, prohibited except as a break-glass fallback recorded in the runbook.
  3. Every user maintains at least 2 MFA methods on critical accounts (Google Workspace, AWS, GitHub) so losing one does not lock them out.

3. Storage

  1. Personnel store their passwords in the Rex Black Vault or an approved password manager.
  2. Plaintext passwords are never written to text files, emails, Slack messages, or tickets. If a shared credential must be handed off, it is shared through the Vault's per-user share flow.

4. Break-glass accounts

  1. Two sealed-envelope break-glass accounts exist:
    • AWS root.
    • GitHub organization owner.
  2. Credentials are stored by the CEO in a physical safe and mirrored to legal counsel. Opening an envelope triggers an incident and immediate rotation after use.

5. Enforcement & exceptions

  1. Password policy is enforced by identity providers (Google Workspace, NextAuth, AWS IAM).
  2. Exceptions require Security Officer written approval and a compensating control.

6. References

  • 002-access-control-policy.md
  • 008-cryptography-and-key-management-policy.md

7. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center