DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027
This baseline states the minimum security settings for daily work at DNZ Consulting LLC. Every device and every account must meet it.
1. Scope and ownership
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
2. Screen locking
The screen locks after 5 minutes of inactivity.
Unlocking needs a password or a biometric check.
Lock the screen before you leave the device, even for a moment.
3. Password complexity
A password is at least 14 characters long.
A password is unique. Never reuse a password across services.
A password manager generates and stores every password. We use the macOS Keychain and Apple Passwords.
Never write a password in a document, a chat message, or source code.
Change a password immediately if it may have leaked.
4. Multi-factor authentication
Turn on multi-factor authentication for every account that offers it.
This is mandatory for email, cloud hosting, source control, the domain registrar, banking, and every merchant platform.
Prefer an authenticator application or a hardware key. Avoid SMS codes where an alternative exists.
Store recovery codes in the encrypted password manager.
5. Clear desk and clear screen
Do not leave a printed document that holds personal data on the desk.
Store paper records in a locked drawer.
Shred a paper record that holds personal data before disposal.
Position the screen so that a visitor cannot read it.
6. Secrets
Store every API key, token, and certificate in the macOS Keychain or in the platform secret store.
Never commit a secret to source control.
Rotate a secret immediately if it appears in a log, a chat, or a file.
7. Email and phishing
Check the sender address before you act on a request.
Never approve a payment or a credential change from an email alone. Confirm on a second channel.
Report a suspected phishing message under the incident response policy.
8. Review
The Managing Member reviews this baseline one time each year.