Compliance checklist for password sharing
Most organizations have policies around password creation — length, complexity, rotation frequency. Far fewer have clear policies around how passwords are shared. This gap creates compliance exposure that is often invisible until an audit or incident makes it visible.
This checklist is designed to help security managers, IT leads, and compliance officers assess their current state and identify the most pressing areas for improvement.
Section 1: Policy and governance
- [ ] We have a written policy prohibiting credential sharing via email, SMS, or uncontrolled messaging applications
- [ ] The policy specifies which tools are approved for credential sharing
- [ ] The policy defines maximum expiry times for shared credential links (e.g., 24h for external, 72h for internal)
- [ ] The policy requires credential rotation after any sharing event with an external party
- [ ] The policy is reviewed at least annually
- [ ] All staff have acknowledged the policy (training record or signature)
- [ ] The policy applies to contractors and freelancers, not just employees
Section 2: Technical controls
- [ ] Credentials are never transmitted in plain text over any channel
- [ ] The credential-sharing tool encrypts data at rest and in transit
- [ ] Credentials are automatically deleted after retrieval (one-time access)
- [ ] Credential links expire after a defined maximum period, even if not retrieved
- [ ] There is no persistent copy of shared credentials in email servers, chat logs, or shared documents
- [ ] The tool used for credential sharing is hosted within the EU (or your required jurisdiction)
Section 3: GDPR and regulatory compliance
- [ ] We have identified all credential-sharing activities that involve personal data systems
- [ ] A Data Processing Agreement (DPA) is in place with the credential-sharing tool provider
- [ ] The tool provider's data residency is documented and meets our regulatory requirements
- [ ] Credential sharing activities are included in our Article 30 Records of Processing Activities (where applicable)
- [ ] We can demonstrate appropriate technical measures under Article 32 GDPR if required
- [ ] Data Subject Access Requests (DSARs) have been considered in the context of credential sharing records
Section 4: Operational security
- [ ] Credentials are rotated immediately after a staff member with access to them leaves the organization
- [ ] Credentials are rotated after sharing with any external party once their access is no longer needed
- [ ] Shared credentials for shared service accounts are individually attributed where possible
- [ ] Emergency access procedures exist that do not require plain text credential sharing (e.g., break-glass accounts)
- [ ] Privileged credentials (root, admin) follow stricter sharing controls than standard credentials
- [ ] There is a process for verifying recipient identity before sharing highly sensitive credentials
Section 5: Incident response
- [ ] We have a defined process for responding to suspected credential compromise
- [ ] The process includes immediate revocation and rotation of affected credentials
- [ ] The credential-sharing tool selection considered breach notification capabilities
- [ ] We have tested our credential compromise response process in the past 12 months
- [ ] There is a record of which credentials were shared with which parties, to support breach scope assessment
Section 6: Vendor and third-party management
- [ ] We have assessed the security practices of all credential-sharing tool providers
- [ ] Vendor assessments include data residency, encryption practices, and deletion guarantees
- [ ] We re-assess tools annually or after significant incidents
- [ ] Contracts with tool providers include security and data protection obligations
Scoring your assessment
Count your checked items:
- 45+ checked: Strong credential security posture. Review remaining gaps annually.
- 30-44 checked: Moderate posture with identifiable gaps. Prioritize Section 2 and 3 items.
- 15-29 checked: Significant gaps exist. Address policy and technical controls as a priority.
- Under 15 checked: High risk. Begin with a basic tool adoption and policy communication immediately.
The most impactful single change
If you can only make one improvement, it is this: adopt a dedicated credential-sharing tool with one-time links, and make email-based credential sharing against policy. This single change addresses the majority of risks in Sections 1-3 and creates a foundation for the remaining items on the checklist.
PassTransfer provides the technical foundation. The organizational work — policy, training, and enforcement — is what you build on top of it.