Writing it down.
WHAT TO STATE
Individual accounts only, no sharing Unique passwords, through a password manager Two-factor authentication required on specified systems Minimum access for each role Access removed the day someone leaves How credentials may be shared, and how they may not
KEEP IT SHORT
One page. Longer is not read.
WHAT ELSE TO INCLUDE
Who to tell if something looks wrong That reporting a mistake is welcome
THAT LAST POINT
Staff who fear blame hide problems.
Say explicitly that reporting a suspected compromise is the right thing to do.
WHAT TO PROVIDE ALONGSIDE
A password manager for the business Training on how to use it
WITHOUT THAT
The policy is unenforceable. People cannot comply without the tool.
WHAT TO REVIEW
Annually, and when systems change.
WHO IT APPLIES TO
Everyone, including you.
Staff follow what you do.