3 ms·
I agree 100% with these complaints about some of us don't have a choice. For example, PCI requires: - Contain both numeric and alphabetic characters. - Users
by sontek 10y ago
I agree 100% with these complaints about some of us don't have a choice. For example, PCI requires:
- Contain both numeric and alphabetic characters.
- Users to change passwords at least every 90 days.
- Password parameters are set to require that new passwords cannot be the same as the four previously used passwords.
Which go against the NIST guidelines. So how do you do things that are considered "best practices" when people like PCI require you to do them wrong?
- Artemis2 10y agoI assume you are referring to the NIST SP 800-63-3, which is quite new (still a draft). PCI DSS follows NIST guidelines quite closely. Requirement 8.2.3 reads "refer to industry standards (e.g., the current version of NIST SP 800-63.)". These requirements will probably be updated at the next version of the standard (and I hope they will!).
- paulddraper 10y agoCorrect. Once the NIST draft is finalized, PCI standards will likely change quickly.