Identity policy templates and rollout checklists
Adaptable starting points — a password and authentication policy outline, an access-management policy, and a phased rollout checklist — grounded in the standards, ready to tailor.
How to use these
These are skeletons, not drop-in documents. Adapt them to your org's risk appetite, regulatory context, and tooling — then get them approved and enforced. Each maps to the deeper playbooks in this collection; a template without enforcement and monitoring behind it is decoration.
Password & authentication policy (outline)
- **Scope** — which accounts and systems this covers (staff, contractors, service accounts, admins).
- **Password requirements** — minimum length 12+ (support 64+), no composition rules, no forced periodic rotation, breach-list screening, full character set allowed, paste and password managers allowed. (See modern password policy.)
- **Storage** — salted + memory-hard hashing (Argon2id/bcrypt/scrypt/PBKDF2); no plaintext or reversible storage.
- **MFA** — phishing-resistant MFA (FIDO2/passkeys) required; SMS deprecated; admins first. (See MFA at scale.)
- **Anti-automation** — rate-limiting, lockout/backoff on failed attempts.
- **Recovery** — phishing-resistant recovery; hardened helpdesk verification; no security questions.
- **Prohibited** — password sharing, reuse across systems, hardcoded credentials.
Access management policy (outline)
- **Access model** — RBAC with defined role ownership; least privilege as default.
- **Provisioning** — driven by joiner-mover-leaver from an authoritative source; birthright vs requestable access.
- **Privileged access** — PAM with just-in-time elevation, session recording, MFA at elevation; no standing admin.
- **Segregation of duties** — conflicting permissions must not co-exist in one role.
- **Deprovisioning** — same-day revocation on termination; token/session revocation, not just account disable.
- **Recertification** — periodic access reviews with auto-revoke of un-reaffirmed access.
- **Non-human identities** — service accounts, tokens, and API keys inventoried and governed like human ones. (See RBAC & JML.)
Write policies against outcomes and standards, not products
Reference the standard (NIST SP 800-63B, CISA phishing-resistant MFA) and the outcome ("phishing-resistant MFA required for all privileged access") rather than a specific vendor. That keeps the policy durable as tooling changes and makes compliance mapping straightforward.
Phased rollout checklist
- **Baseline & inventory** — current password policy, MFA coverage, privileged accounts, sending domains, certificate estate, key inventory.
- **Quick wins** — turn off forced password expiry; disable legacy authentication; enforce MFA for admins.
- **Deploy in monitor mode** — new password policy in audit mode; DMARC at p=none; conditional access in report-only.
- **Remediate from the data** — fix breach-screening rejections, DMARC-failing senders, non-compliant devices before enforcing.
- **Enforce in waves** — phishing-resistant MFA (admins → high-risk → all), DMARC to p=reject, device-compliance gating.
- **Monitor & recertify** — SIEM detections live, access recertification scheduled, metrics reported.
- **Communicate throughout** — explain the why (fewer forced changes, managers allowed, stronger protection) to keep users on side.
Sign-off checklist before calling it done
Policy approved by an accountable owner; enforcement mechanism identified for every rule (not just documented); monitoring/detection in place for each control; metrics and recertification scheduled; exceptions logged with expiry and owner. A policy with no enforcement and no metric behind it is not implemented.