4 ms·
Interesting how many corporate security policies act like they don't even know NIST exists. Password rotations for users are audit crown jewels but recommended
by davio 6y ago
Interesting how many corporate security policies act like they don't even know NIST exists. Password rotations for users are audit crown jewels but recommended against by NIST
- zinekeller 6y ago50% company doesn't know or care, 50% the company knows and wants to implement security but the auditors are stuck in 2005 (PCI Compliance: unless you somehow documented clearly your 'mitigations' because you are NOT rotating your passwords, you fail somehow).
- moyix 6y agoThe problem is really the opposite – too many organizations slavishly follow the pre-2017 NIST guidance! Per wikipedia: > From 2004, the “NIST Special Publication 800-63. Appendix A,”[2] advised people to use irregular capitalization, special characters, and at least one numeral. It also recommended changing passwords regularly, at least every 90 days. This was the advice that most systems followed, and was "baked into" a number of standards that businesses needed to follow.
- kevinarpe 6y agoI agree. I cannot recall a single corporate password policy in my working life that did not require regular password resets. And now that I think about it, I am surprised that Google does not ask me to reset my password on a regular basis. I guess Google follows the latest NIST advice! (For other readers: It seems that quote comes from here: https://en.wikipedia.org/wiki/Password_policy https://en.wikipedia.org/wiki/Password_policy)
- godtoldmetodoit 6y agoNIST used to recommend password rotations not that long ago, pretty recent change. I work in a compliance heavy environment and have tried getting the rotation policy changed, but it's baked into so many contracts at this point it will take another 5+ years before we to the ~2018 era guidelines.
- flubert 6y ago>recommended against by NIST As a layman who has too many passwords that rotate too often to keep in memory effectively, I'd like to pass this along to our IT department. Can someone post a link to the NIST best password practices?
- kevinarpe 6y agoThis PDF is dated June 2017: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
- amanzi 6y agoIt's also important to note that password rotations are not recommended by NIST as long as the other guidance is also being followed, i.e. password length requirements. I've seen people quote small sections of NIST recommendations while missing out on the context.