LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Authentication and Password Policy

Public security and assurance reference

POL-2: Authentication and Password Policy

Purpose

This policy defines the requirements for authenticating users and managing credentials to protect LNC Nexus systems and data. It ensures that strong authentication mechanisms are in place to prevent unauthorized access and maintain trust in legal-medical analysis.

Scope

This policy applies to all users accessing LNC Nexus hosted, private, or self-managed deployments. It covers passwords, multi-factor authentication, and credential management for administrative and end-user accounts.

Policy Statements

All users must authenticate using strong passwords or multi-factor methods. Passwords shall meet complexity requirements and be changed periodically. Administrative access requires multi-factor authentication. In self-managed deployments, customers are responsible for enforcing authentication standards; LNC Nexus provides the mechanisms but not the enforcement. Credentials shall never be shared, and default passwords must be changed immediately upon deployment.

Roles and Responsibilities

The Security Team defines authentication standards and monitors compliance. Users are responsible for safeguarding their credentials and reporting suspected compromises. System administrators enforce authentication requirements and manage credential lifecycle.

Evidence and Review

Authentication logs, password change records, and multi-factor enrollment data serve as evidence of compliance. The Security Team conducts periodic reviews of authentication practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Access may be suspended immediately upon detection of a violation.

POL-1 (Access Control Policy), POL-7 (Encryption Policy), POL-14 (Human Resources Security Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft