EventX Password Policy Guidelines

EventX Password Policy Guidelines

Creating strong, secure passwords is essential for protecting sensitive information and systems. This guide outlines best practices for setting and managing passwords in a way that balances security and usability of your Organization account.

1. Minimum Password Length

  • Requirement: Passwords must be at least 8 characters long.

  • Recommendation: Encourage longer passwords or passphrases (e.g., "BlueCoffee!Table1985") for better security and memorability.


2. Complexity Requirements

  • Allow passwords to include a mix of uppercase and lowercase letters, numbers, and special characters.

  • Do not require users to include specific character types (e.g., one uppercase, one number). Instead, promote the use of longer and more memorable passphrases.

✅ Good: CorrectHorseBatteryStaple
❌ Poor: Password1! (too predictable)

  • Avoid predictable patterns or sequences, such as:

    • Common substitutions (e.g., P@ssw0rd)

    • Repeating characters (e.g., aaa111)

    • Keyboard patterns (e.g., qwerty, asdf1234)

3. Deny List for Common Passwords

  • Prohibit the use of:

    • Commonly used passwords (e.g., 123456, password)

    • Breached or compromised passwords

  • Implement a deny list based on real-world password breach data and continuously update it to reflect current threats.

4. Password Expiration Policy

  • Do not enforce routine password expiration (e.g., every 90 days), as this often results in weaker or predictable variations (e.g., Spring2025Summer2025).

  • Require password changes only when there is evidence of compromise, such as a data breach or suspicious activity.

5. Enterprise  Support

Organizations on the Enterprise Plan have the flexibility to define their own custom password policy settings. This allows alignment with internal security standards or industry-specific compliance requirements.

    • Related Articles

    • EventX Data Protection and Security

      The EventX platform has been built for ultra-safe and secure performance. Protecting your data is paramount to us. Since May 25, 2018, EventX has complied with the EU’s General Data Protection Regulation (GDPR) privacy law. Our privacy policy and ...
    • EventX Lead Finder Data Overview

      How Is EventX Data Sourced and Collected? EventX guarantee that we will never sell the data of attendees provided by the organizer. EventX data isn't single-sourced, there are 2 main ways in which EventX collects data: Public Data Crawling: EventX ...