Nick_Parker Posted May 12, 2011 Posted May 12, 2011 Hi everyone, Does anybody have a document or know somewhere that I can find a Standard Password Practices / Policy? We recently had an audit and they said that there is a flaw in our IT security as staff do not change their passwords often enough. At the moment we force a change every 90 days, minimum of 4 characters and the last password is remembered. What does everyone else use?
mac_shinobi Posted May 12, 2011 Posted May 12, 2011 Where I work as far as I am aware * At least 8 characters long * Must contain at least an uppercase character * Must contain at least 2 numerical digits ie 29 * Changes more frequently ( Think its 60 days as apposed to 90 ) * Remembers the last 28 passwords ( which imo is too much ) - changing this to say 10 or even 5 would be good * Also we don't do this as far as policy etc but I normally include at least a symbol whether its a space, ampersand, etc
mjs_mjs Posted May 12, 2011 Posted May 12, 2011 here its; * 6 character min, * changes every 42 days, * last 10 passwords remembered. irrc.
bio Posted May 12, 2011 Posted May 12, 2011 The SANS whitepapers are allways a good place to start. bio...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now