>>Blog - All Posts<<,  Auditing/Compliance,  NIST

Have You Heard the New Password Recommendations by NIST?

You have heard a longer password is better, but what if you were told you didn’t “need” a special character or capital letter? That is part of the recommendations set by NIST. They now recommend having at least 15 characters minimum since the length of a password is the most important. This is due to the amount of time a computer needs to crack a 15 character password without locking the account after a set number of failed attempts. Also, NIST does not recommend updating your password every 3 months. It may seem surprising, but users who reset their passwords quarterly will create new passwords with reduced complexity that are “easier” to remember instead of creating a completely new high-quality password.

NIST Provides 3 Tips to Secure Online Accounts

1.) Set up multifactor authentication. Passkeys are a great option.

2.) Use a password manager.

3.) If you must make a password, make sure it’s at least 15 characters long. A passphrase can help you come up with something long and memorable.

My List of User Vulnerability

1.) Users can lack a concern for protecting the information they are responsible for.

2.) Users will rely on memory to store their passwords or write it down on a sticky note posted on their computer screen.

3.) Users will lack knowledge of the importance of high-quality passwords and the vulnerability of poor passwords. Users will also fail to keep passwords secret to themselves and may freely share it with others.

The remedy for helping users is the training of users, enforcing password requirements, and providing password managers to users will greatly benefit the overall security of information. I also believe that users should be informed by their employers that they are responsible for keeping their login information private and secure. Also, if breaches happen through their account that their may be ramifications.

You can learn more from their article here where they provide further explanations, which I highly recommend. And please feel free to post your thoughts on this.

NIST LINK >>>> https://www.nist.gov/cybersecurity/how-do-i-create-good-password

Leave a Reply

Your email address will not be published. Required fields are marked *