Last materially reviewed: September 3, 2026
Direct Answer
A business password policy should require unique credentials, company-approved password management, MFA for important systems, controlled recovery methods and rapid removal of access when employees leave. The policy should focus less on arbitrary password-changing schedules and more on preventing reuse, protecting high-value accounts and responding quickly when credentials are exposed.
Key Takeaways
- Require unique passwords for every important system.
- Use a business password manager instead of shared spreadsheets or chat messages.
- Enable MFA for email, cloud, finance and administrator accounts.
- Avoid routine forced password changes unless there is a reason or system requirement.
- Change credentials immediately after suspected compromise.
What should the policy cover?
- Password creation and uniqueness
- Approved password manager
- MFA requirements
- Shared/service-account handling
- Administrator credentials
- Recovery codes and reset methods
- Offboarding and access removal
- Response to credential leaks
Password length and strength
Long, unique passwords or passphrases are generally more useful than short complex passwords that employees reuse. Systems should prevent use of known weak passwords where possible. Employees should never reuse business passwords for personal services.
Password managers
A company-controlled password manager can generate and store unique credentials, support secure sharing and reduce the temptation to reuse passwords. Administrator access to the password manager itself should be strongly protected with MFA.
MFA is part of the password policy
Passwords alone should not protect critical systems. Require MFA for email, cloud administration, finance, domain registrar, payroll, remote access and other high-impact accounts. See Multi-Factor Authentication Guide.
Shared accounts
Replace shared logins with named accounts where possible. If a service account must be shared, control it through a password manager, restrict who can access it, rotate credentials after staffing changes and log use where the system allows.
Administrator accounts
Do not use administrator credentials for routine browsing and email where separate accounts are supported. Keep admin access limited, monitored and protected with stronger recovery controls.
When should passwords be changed?
Change passwords after suspected compromise, credential exposure, unauthorized sharing or when someone with access leaves. Routine forced changes can encourage predictable passwords if there is no evidence-based reason for them.
Privacy and security obligations
The Data Privacy Act requires reasonable and appropriate security measures for personal data. NPC guidance specifically references strong authentication and password policies as part of technical security. A written password policy should therefore connect to broader access-control and information-security policies.
FAQs
Should employees write passwords on paper?
Business credentials should be stored using approved secure methods. A managed password manager is usually more scalable and auditable than handwritten or spreadsheet storage.
Can two employees share one password?
It is better to use named accounts. Shared credentials weaken accountability and make offboarding harder.
Is a strong password enough without MFA?
No. MFA significantly reduces risk when passwords are stolen or phished.
Related Cybercode Guides
Official Sources
Disclaimer
Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology, or business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety, or legal exposure may be affected.

