> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blevinsholdings.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Policy

> Information security requirements and responsibilities for all Blevins Holdings personnel.

<Info>Last reviewed: \[Date] — Next review due: \[Date]</Info>

## Password requirements

| Requirement    | Standard                              |
| -------------- | ------------------------------------- |
| Minimum length | 14 characters                         |
| Complexity     | Mix of upper, lower, numbers, symbols |
| Reuse          | No reuse of last 10 passwords         |
| Rotation       | Every 90 days for privileged accounts |
| MFA            | Required on all company accounts      |

<Tip>
  Use a company-approved password manager. Do not store passwords in browsers, spreadsheets, or sticky notes.
</Tip>

## Device security

* Enable full-disk encryption on all devices used for company work
* Keep operating systems and software up to date — do not defer updates beyond 7 days
* Do not connect company devices to unknown or public Wi-Fi without using the company VPN
* Report lost or stolen devices to IT immediately: [it@blevinsholdings.com](mailto:it@blevinsholdings.com)

## Access control

Access to systems and data is granted on a least-privilege basis — you receive only the access needed for your role. Access is reviewed quarterly and revoked promptly upon role changes or departure.

Requesting additional access:

```bash theme={null}
# Submit via the IT helpdesk portal
# Include: system name, access level needed, business justification, manager approval
```

## Phishing and social engineering

If you receive a suspicious email:

<Steps>
  <Step title="Do not click links or download attachments">
    Even if the sender appears to be someone you know.
  </Step>

  <Step title="Report it">
    Forward the email to [security@blevinsholdings.com](mailto:security@blevinsholdings.com) or use the "Report Phishing" button in your email client.
  </Step>

  <Step title="Delete it">
    After reporting, delete the email from your inbox and trash.
  </Step>
</Steps>

<Warning>
  IT will never ask for your password via email, phone, or chat. If someone does, report it immediately.
</Warning>

***

*Policy owner: IT Security*
