01 · Explanation
Passwords, MFA, and account recovery
Objective: Apply organization-approved authentication, recovery, access, and offboarding controls to high-value accounts and eliminate insecure credential handling.
Start with the accounts that can change money, identity, email, domains, cloud configuration, customer data, payroll, source code, or other access. Use unique passwords generated and stored in an organization-approved password manager, and enable the strongest practical multi-factor method approved for the service. Phishing-resistant methods such as hardware-backed authenticators or passkeys can provide stronger protection than codes that users may be tricked into relaying. Never share passwords or one-time codes by email, chat, phone, or document. Service and shared accounts require named ownership, scoped permissions, monitored use, and a controlled alternative to informal shared credentials.
Recovery is part of authentication. Inventory recovery email, phone, backup codes, administrators, vendor support routes, and proof required for high-value services. Protect recovery channels at least as carefully as the account they restore. Test the documented process without locking out production work, and store emergency material securely with limited, auditable access. Joiner, role-change, and leaver workflows should grant, review, and revoke access promptly. Review privileged access and inactive accounts on a schedule. Exact authentication requirements depend on risk, service capabilities, and applicable obligations; security and identity specialists should approve high-assurance or regulated implementations.
Before you begin
- Confirm F03-F09; record that the identity provider, affected account list, approved incident playbook, clean administrative workstation, session/token inventory, forensic direction, and containment results are not supplied.
- STOP. If the identity provider, affected accounts, approved playbook, trusted workstation, session/token inventory, or forensic direction is missing or conflicts across F03–F09, route containment to authorized security leadership and the incident coordinator; do not claim approval or execute credential, session, mailbox, privilege, or device changes.

