Skip to main content
DraftIndicative placeholder for the section owner — amend, replace, or confirm as the first definitive version.

Doc owner: Security Officer

Password manager

How to manage Allied credentials safely. The definitive requirements live in POL-DIG-004 Password Policy — this guide is the practical companion.

TBD — reviewer to confirm the current standard. POL-DIG-004 references LastPass as the legacy provision and flags that the org standard needs verifying. Update both this guide and the policy once the decision is recorded.

Requirements (from POL-DIG-004)

  • Passwords are at least 12 characters and difficult to guess.
  • Every password is unique — never re-used across accounts.
  • Use the password manager's generator for every new credential.
  • Default passwords are changed on first use.
  • Multi-factor authentication is mandatory wherever supported — see Authenticator.
  • Suspected compromise — reset the password immediately and warn others via the Allied security Slack channel.

Quick start

  1. Install the desktop app, browser extension, and mobile app for your password manager.
  2. Create a strong master password (unique, ≥ 12 characters — a passphrase is fine).
  3. Sign in with your licence or account credentials.
  4. Import existing passwords (CSV or direct import) if migrating.
  5. Enable multi-factor authentication on the password manager itself.

Best practices

  • Store all credentials in the vault — work, personal, shared.
  • Generate long, random passwords for every site.
  • Review and rotate high-risk or re-used passwords at least quarterly.
  • Use vault sharing for team accounts — never email credentials.
  • Keep the apps updated.