Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Evaluate the 12-character password requirement #253

Open
adhilto opened this issue Apr 3, 2024 · 4 comments
Open

Evaluate the 12-character password requirement #253

adhilto opened this issue Apr 3, 2024 · 4 comments

Comments

@adhilto
Copy link
Collaborator

adhilto commented Apr 3, 2024

With regard to GWS.COMMONCONTROLS.5.2, what is the motivation for the number 12? More is obviously stronger, but NIST guidance specifies 8 characters (https://pages.nist.gov/800-63-3/sp800-63b.html). Is there a specific reason we're deviating from NIST guidance (beyond "more is better")?

@jkaufman-mitre
Copy link
Collaborator

@adhilto I will talk to our team as I was not around when that policy was initially created.

@jkaufman-mitre
Copy link
Collaborator

@adhilto I am wondering if they got that number from this Google article:

@jkaufman-mitre
Copy link
Collaborator

@adhilto After discussion internally, we are going to keep it at minimum as 12 and cited the google recommendation from the article above. Even though NIST says 8 characters, Google says 12 and DISA standards is 15.

@buidav
Copy link
Collaborator

buidav commented Apr 10, 2024

Recommend we add that link and add to the rationale where the number came from.

As the Common Controls 5.2 policy currently sits there is no reference to that article in the resource links and the justification for the password 12 character limit is NIST 600-63B which is recommending only 8 characters.
60053B

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants