this post was submitted on 20 Aug 2024
600 points (98.9% liked)
Cybersecurity - Memes
1989 readers
2 users here now
Only the hottest memes in Cybersecurity
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Which certifications? NIST standards don't recommend regular rotations anymore.
Nist guidelines used to recommend rotation, and our security team would quickly point to it when people complained.
So of course we jumped on that and security team said "well nist are just guidelines and we go for more stringent requirements"...
I would need to check (not in charge of it), but I do remember in the fat stack of guidelines we got there was the password policy of 90 days. However, the point still stands that some people have no digital hygiene and will write down and share their passwords in plain text for all to see even if we didn't enforce password expiry. Though in all honesty, there's no winning combination when so many don't truly give a shit about digital security. As long as they can flaunt a certificate.