vStream Digital Media / ShineVR

Password Policy

Date: 03 February 2025
Owner: Andrés Pitt, CTO
Next Review Date: February 2026
Approved By: Andrés Pitt, CTO

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
Usermeans any employee, contractor, temporary staff, or authorized third party with access to Company or ShineVR systems

1. Policy Statement

vStream Digital Media is committed to protecting its information systems and data through strong password security practices. This policy establishes mandatory password requirements for all users accessing Company and ShineVR systems to prevent unauthorised access and protect against brute-force attacks.

All password requirements are enforced through Google Workspace centralised password management, ensuring consistent application across all Company and ShineVR systems.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

This policy covers:

4. Password Requirements

4.1 Minimum Password Length

4.2 Password Complexity

4.3 Password Refresh Cycle

4.4 Password History and Reuse

4.5 Account Lockout

5. Password Storage And Transmission

5.1 Password Storage

5.2 Password Transmission

5.3 Password Sharing

6. Special Account Types

6.1 Privileged Accounts

6.2 Service Accounts

6.3 Third-Party Supplier Accounts

7. Multi-Factor Authentication (MFA)

8. Password Security Best Practices

Users must:

Users must not:

9. Password Compromise And Incident Response

9.1 Suspected Compromise

If a user suspects their password has been compromised, they must:

  1. Immediately change their password
  2. Report the incident to the CTO (andres@vstream.ie)
  3. Review recent account activity for unauthorised access

9.2 Confirmed Compromise

If password compromise is confirmed:

9.3 Monitoring for Compromised Credentials

10. Enforcement

10.1 Google Workspace Enforcement

All password requirements are technically enforced through Google Workspace settings:

10.2 Compliance Monitoring

10.3 Policy Violations

11. Exceptions

Any exception to this policy must:

12. Policy Review

13. Responsibilities

RoleResponsibilities
CTO (Responsible Person)Overall policy ownership; Google Workspace configuration; incident response; policy review; exception approval
All UsersComply with password requirements; protect credentials; report compromised passwords; complete security awareness training
Line ManagersEnsure team members understand policy; monitor compliance; report violations
IT AdministratorsConfigure password enforcement; unlock accounts; monitor alerts; maintain audit logs

14. Related Policies

This policy should be read in conjunction with:

15. Training And Awareness

16. Contact Information

For questions regarding this policy or to report password security incidents:

Data Protection Officer / CTO Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570