Secure Device Access with Passwords/PINs 

Advice:
  • Require strong passwords, passphrases, or biometric authentication (such as fingerprint or facial recognition) to access devices. This measure significantly increases security, especially if the device is lost or stolen, as it prevents unauthorized access.
  • Avoid using simple or common passwords, and discourage sharing of access credentials among users.
Guideline:
  • Strong Password Policies: Establish policies that require strong passwords consisting of at least 12-16 characters, including uppercase and lowercase letters, numbers, and special characters. Utilize tools to enforce password complexity requirements.
  • Automatic Locking: Ensure that device lock settings are enabled to automatically lock the device after a period of inactivity (e.g., 5 to 15 minutes). This is especially important in environments where devices may be left unattended.
  • Disable Default Passwords: Change any default credentials when setting up devices, including routers, printers, or IoT devices, which are often targeted by cybercriminals. Ensure that the new passwords adhere to established strong password policies.
  • Two-Factor Authentication: For an added layer of protection, implement two-factor authentication (2FA) where available on device access, requiring not just a password but also a second factor, such as a text message code or authentication app prompt.