Authentication Policy
This policy is the Authentication Policy referred to in the UK Participation Agreement between Digital Completion UK Limited and (as applicable) the Participant or the Customer (Participation Agreement).
Terms which are defined in the Participation Agreement have the same meaning when used in this Authentication Policy.
The Participant or Customer (as applicable) must ensure that:
- User passwords contain a minimum of eight (8) characters and satisfy at least three of the following:
- the password includes at least one (1) uppercase letter;
- the password includes at least one (1) lowercase letter;
- the password includes at least one (1) number (0-9); and
- the password includes at least one (1) special character;
- Users cannot use a previously used password when setting a new password;
- Users are locked out after multiple consecutive incorrect login attempts;
- the unlock process is secure and involves User verification;
- the password reset process is secure;
- password expiry periods are enforced;
- there is a system idle lockout duration in place;
- Multi-factor authentication is required for application access;
- Users require an organisational VPN for application access; and
- Users who have left the organisation are deactivated from the organisation’s network in a timely manner.