DraftIndicative placeholder for the section owner — amend, replace, or confirm as the first definitive version.
Doc owner: Security Officer
Password manager
How to manage Allied credentials safely. The definitive requirements live in POL-DIG-004 Password Policy — this guide is the practical companion.
TBD — reviewer to confirm the current standard. POL-DIG-004 references LastPass as the legacy provision and flags that the org standard needs verifying. Update both this guide and the policy once the decision is recorded.
Requirements (from POL-DIG-004)
- Passwords are at least 12 characters and difficult to guess.
- Every password is unique — never re-used across accounts.
- Use the password manager's generator for every new credential.
- Default passwords are changed on first use.
- Multi-factor authentication is mandatory wherever supported — see Authenticator.
- Suspected compromise — reset the password immediately and warn others via the Allied security Slack channel.
Quick start
- Install the desktop app, browser extension, and mobile app for your password manager.
- Create a strong master password (unique, ≥ 12 characters — a passphrase is fine).
- Sign in with your licence or account credentials.
- Import existing passwords (CSV or direct import) if migrating.
- Enable multi-factor authentication on the password manager itself.
Best practices
- Store all credentials in the vault — work, personal, shared.
- Generate long, random passwords for every site.
- Review and rotate high-risk or re-used passwords at least quarterly.
- Use vault sharing for team accounts — never email credentials.
- Keep the apps updated.