Strong password requirements are formally defined and communicated
Among A.5.1's topic-specific policies, Sekit's Password policy sets minimum length, bans reuse across services, and requires a password manager for staff credentials.
Documenting minimum length, no reuse, mandatory password-manager use and shared-credential handling supports A.5.17's authentication information requirement, though credential issuance and non-human secrets are covered by other controls.
https://sekit.ai/api/mcp/crosswalk