Guidance / Password Policy Gap Review

Password Policy Gap Review

A focused review of existing password rules against how staff actually work, with a ranked list of fixes before a full rollout.

Notebook and policy documents open beside a laptop during a gap review

Who it is for: Organisations with a draft or outdated password policy that needs a reality check

Result: A concise findings memo and recommended wording changes before you publish

Format: Document review plus stakeholder interviews

Duration: 5–8 business days

Location: Remote with optional site visit

Pricing basis: Fixed review fee

Send your current policy for a scoping reply.

Included

  • Review of current written rules
  • Interviews with two to four role holders
  • Prioritised change list with plain-language rationale

Outside this engagement

  • Full security audits of networks or servers
  • Writing of unrelated IT policies

How the work unfolds

  1. Collect documents and system notes
  2. Interview and observe common access patterns
  3. Deliver findings and optional rewrite support

Preparation: Send the latest policy PDF and any exception lists you already keep.

Constraints: One primary policy document per review engagement.