| Require unique passwords for business systems. | | |
| Do not allow business passwords to be shared through email, text, chat, sticky notes, or spreadsheets. | | |
| Use an approved business password manager for shared business credentials. | | |
| Require Multi-Factor Authentication for email, administrator accounts, accounting, payroll, cloud storage, and password manager access. | | |
| Avoid shared accounts whenever named user accounts are available. | | |
| Document any approved shared account exceptions. | | |
| Remove password manager access when an employee leaves. | | |
| Change shared passwords known by a former employee. | | |
| Review administrator passwords and privileged access regularly. | | |
| Document the policy review date and next review date. | | |