Password policy
set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly

A password policy is a set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly. A password policy is often part of an organization's official regulations and may be taught as part of security awareness training. Either the password policy is merely advisory, or the computer systems force users to comply with it. Some governments have national authentication frameworks that define requirements for user authentication to government services, including requirements for passwords.
International guidelines
ISO/IEC 27001 in the ISO/IEC 27000 family is used globally, as is the United States NIST standard. It can help prevent faulty password security. More specific is ISO/IEC 27002#Access control.
National guidelines
United States (NIST)
The United States Department of Commerce's National Institute of Standards and Technology (NIST) has put out two standards for password policies which have been widely followed.
2004
From 2004, the "NIST Special Publication 800-63. Appendix A," advised people to use irregular capitalization, special characters, and at least one numeral.
“Password policy” enters the record as set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly. Crown Archives preserves that source wording while asking what Password, policy and rules can confirm, complicate or overturn.
Why this record matters
“Password policy” is worth following because a concise public description often conceals a longer documentary argument. Here, Password, policy and rules provides the most credible route into that argument.
The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Sep 10, 2026. The linked authority identifier is Q3394687. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2004.
Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Password policy”, its source revision and the description used here.
- Expand the search: follow Password policy primary sources, Password policy archive and Password research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Password policy”?
- What terminology or title could unlock a more precise catalogue search?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “Password policy” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.