ITGC – Password Management Testing

ITGC – Password Management Testing

πŸ”§Password Management

🧭 Planning:
Reviewed system authentication configurations and password policy enforcement across key platforms (Active Directory, ERP systems, and internal applications) as part of an ITGC audit cycle.


🎯 Objectives:

  • Confirm password policies enforce minimum complexity and expiration

  • Assess lockout mechanisms and reset procedures

  • Validate use of multi-factor authentication (MFA)

  • Identify risks from weak or default credentials


πŸ“Œ Procedures:

  • Reviewed password configuration for 3 core systems

  • Evaluated lockout settings and retry limits

  • Tested reset request processes for end-users and admins

  • Checked for unused or default accounts

  • Reviewed MFA deployment across user groups


πŸ“‘ Working Papers:

  • WP-ITGC-PWD001: Password policy configuration & enforcement

  • Screenshots from system settings, reset logs, and MFA reports


πŸ“Š Findings:

  • ❗ One system allowed 6-character passwords with no complexity

  • ❗ No lockout policy in place on internal legacy tool

  • ⚠️ Admin password resets lacked consistent identity verification


🧰 Tools Used:

Active Directory, ERP config console, ServiceNow, Excel, MFA portal


βœ… Recommendations:

  • Enforce strong password policies across all systems (min 12 characters, complexity, expiration)

  • Implement lockout thresholds after multiple failed login attempts

  • Apply strict identity verification for all password resets

  • Expand MFA implementation to cover all privileged and sensitive roles

  • Review and update password policies annually

Leave a Reply