Password Protection Policy
The purpose of this policy is to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change. Passwords are an important aspect of computer security. A poorly chosen password may result in unauthorized access and/or exploitation of Ripple Treasury’s resources. All users with access to Ripple Treasury systems, including the PCI Server, are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.
The scope of this policy includes all personnel who are responsible for an account (or any form of access that supports or requires a password) on any system that resides at any Ripple Treasury facility, has access to the Ripple Treasury network, or stores any non-public Ripple Treasury information. Password cracking or guessing may be performed on a periodic or random basis by management or its delegates. If a password is guessed or cracked during these exercises, the user/owner will be required to change it.
Policy
A user’s initial password must be changed.
All user-level passwords (e.g., email, web, computer, etc.) must be changed at least every 90 days.
A user will be locked out after 3 unsuccessful logins. Failed login attempts are logged.
The password will be at least seventeen (17) characters in length.
All user-level and system-level passwords must conform to Ripple Treasury standards.
Passwords should not be shared with anyone, including other employees.
All passwords are to be treated as sensitive, confidential Ripple Treasury information.
Passwords should never be written down or stored online without encryption.
If an account or password compromise is suspected, the incident should be reported immediately.
Computers should always be locked when the user is not present.
Computers should be configured to automatically lock after no more than 15 minutes of inactivity.
If a user has been locked out, automatic unlocking should occur after 30 minutes or administrator intervention.
Video conferencing capabilities (i.e. Zoom, GoToMeeting, etc.) require the use of a password.
Biometrics should not be used in place of a password to log into users’ Ripple Treasury issued device.
USB tokens and certificate passwords are to be utilized as necessary for specific applications, as required per job role. Only certain individuals have access to these password methodologies. Passwords for tokens and certificates should adhere to the same standards as included within the Ripple Treasury Password Policy.
The last eight (8) passwords cannot be reused.
IT must enable password complexity on Windows Operating Systems.
Where available and it does not prevent the application of other password principles, IT must set the minimum password age to 1 day for privileged accounts.
Personal tokens and mobile devices must enforce passwords or Personal Identification Number (PIN) with appropriate parameters.
Default passwords must be changed on newly installed software or operating systems.
Procedures – Users
Users with access to the Ripple Treasury application are responsible for maintaining their own passwords. Clients have the option to change all application password-related settings to match their corporate policies. There are certain password related settings that only Ripple Treasury can modify in the database on behalf of a client (such as password length, minimum character length, minimum numeric characters, and minimum special characters), with written client approval. Requests to change passwords by Ripple Treasury on behalf of a client will be limited to client administrators only, with a request sent in writing on company letterhead (by fax or email attachment) and with a separate email request with a company identifier email address. Password related requests will not be accepted by telephone. Non-administrator password resets are the responsibility of the client administrator. Clients can optionally add features such as SSO (Identity Provider Initiated SAML 2.0) and/or Multi-Factor authentication as an additional security measure.
Procedures – Employees
Employees who have been locked out of the system for any reason should contact IT. IT will verify the identity of the employee prior to establishing a temporary password which can only be used once for the purpose of changing that password to a permanent password. This password, like all passwords will expire in 90 days per policy.
SWIFT Requirements
The number of occurrences of the same character in the password should be equal to or less than half the number of characters in the password minus one (L-1)/2.
Passwords should not contain commonly used sequences or illegal patterns.
Passwords should not contain (in full or in significant part) the ID or the name of the object protected by the password.
Passwords should not consist of easily guessed patterns e.g. words, birthdays, repeating characters, etc.
There is no maximum character length.
Accounts Used by Non-Human Users
Password length of at least 17 characters
Passwords changed at least every 2 years
Passwords should be an unpredictable string (to avoid dictionary attacks)
RSA PIN Code Requirements
Enforce a minimum of 6 characters. This length should opportunistically be increased (to 8) and when possible turned into a password.
No PIN reuse within the previous 5 codes.
No fixed default PIN code.
Should be changeable on user request.
Should require immediate change by the user on initial password allocation or reset if not initialized by the user.
Chosen by User, randomly by system.
PIN are changed at least every 180 days.
Does not consist of commonly used sequences (123456,125634,654321,234567,222222, etc).
Lock out after 5 failed attempts
Copyright 2025 Ripple Labs Inc.
