Center for Internet Security (CIS) Password Recommendations
- 10 character minimum length
- Password complexity: uppercase letters, lowercase letters, numbers, and symbols
- Change passwords at least every 60 days
- Prevent the reuse of the past 24 passwords
- Set the minimum password age to one day (so that users can’t change their password 24 times to reuse their old password)
- Set account login thresholds to 10 or fewer invalid login attempts. (Keep in mind that the fewer attempts you allow the more password related issues your users will have.)
- Change default passwords on accounts when setting up new equipment.
- If a user accesses several accounts, require them to use a separate password for each.
- Do not allow the use of names, user account names, or other personal information in passwords.
- Store all passwords using strong salting and hashing functions.
- Do not store passwords using reversible encryption.
- Train users to use separate passwords for work and personal accounts.
Finding the Right Balance
Summary:
- CMMC does not mention specific password length, complexity, or reset requirements. Your company should decide on them.
- You can not go wrong with password recommendations from the Center for Internet Security.
- C009: Identify and protect audit information
- Before implementing password requirements, think about how they will impact security and productivity.
- If you found this information useful and want to learn more about CMMC reach out to us at info[@]lakeridge.io