Company Policies

The principles that guide every team at Kriko. From how we hire and protect data to how we uphold quality and sustainability.

Password Creation and Use Policy

Purpose

This policy establishes the standards for creating and using passwords to protect the Company’s information assets against unauthorised access. All employees are required to comply with this policy to strengthen the security of the Company’s data and systems.

Password Security

Passwords are required for all employees who have access to personal, confidential or sensitive information. Each employee must create a strong and unique password to access the systems provided by the Company.

Passwords must:

  • Contain at least eight characters.
  • Include uppercase and lowercase letters, numbers and special characters.
  • Be changed regularly, preferably at least once every 90 days.
  • Be unique to each system or account. The same password must not be used across multiple systems or accounts.
  • Not contain easily guessed information or personal details, such as dates of birth, first or last names, or telephone numbers.

Password Protection

Passwords must not be shared with or disclosed to any other person. Each employee is responsible for protecting their own passwords.

Passwords must not be recorded in unsecured written or electronic formats. Employees are responsible for storing and remembering their passwords securely.

Passwords must not be saved in browsers or other applications by using automatic login or password storage features.

Password Changes and Post-Incident Security

Passwords must be changed regularly within the intervals determined by the Company.

Where a password is forgotten or suspicious activity is detected, the applicable password reset procedures must be followed to protect the relevant account.

Reporting Password Breaches

Any suspected password breach or security vulnerability must be reported immediately to the Company’s information security team or the relevant manager.

In the event of a password breach, the affected accounts must be secured immediately, and the relevant passwords must be changed.

Track the digital heartbeat with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.