<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NIST Password Standard in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31464#M2098</link>
    <description>&lt;P&gt;How are organizations screening passwords to be fully compliant with the new NIST standard?&amp;nbsp; A manual process will not work for my organization.&lt;/P&gt;&lt;P&gt;Thanks, Tom&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 13:27:29 GMT</pubDate>
    <dc:creator>apbanohit</dc:creator>
    <dc:date>2020-01-10T13:27:29Z</dc:date>
    <item>
      <title>NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31464#M2098</link>
      <description>&lt;P&gt;How are organizations screening passwords to be fully compliant with the new NIST standard?&amp;nbsp; A manual process will not work for my organization.&lt;/P&gt;&lt;P&gt;Thanks, Tom&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 13:27:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31464#M2098</guid>
      <dc:creator>apbanohit</dc:creator>
      <dc:date>2020-01-10T13:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31465#M2099</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1029517125"&gt;@apbanohit&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;How are organizations screening passwords to be fully compliant with the new NIST standard?&amp;nbsp; A manual process will not work for my organization.&lt;/P&gt;&lt;P&gt;Thanks, Tom&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Tom,&lt;/P&gt;&lt;P&gt;You should not be screening existing passwords. The password polices must first be rewritten to move away from the timed renewal, complexity, and length standards to match the current &lt;A href="https://pages.nist.gov/800-63-3/" target="_blank" rel="noopener"&gt;NIST SP 800-63-3&lt;/A&gt;. Once you have clear guidance in hand, the sysadmins responsible for the IDAM software must change the existing settings on your password registration software to apply the new policies as each user creates a new password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only person applying manual password compliance process to actual passwords should be the user creating the password. If you are not currently using a password approval module in your IDAM software, essentially making compliance with current password policy the responsibility of the end user, then you should continue that simple process, simply telling al users what the new policy is so they can update with better passwords when they wish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh, and make darn sure you update the password registration database to allow for very long passwords that allow at a minimum all keyboard-accessible characters, including spaces and all symbols. Move away from the rules not allowing key script characters as an unnecessary protection against *ix script insertion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 13:47:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31465#M2099</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2020-01-10T13:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31468#M2100</link>
      <description>&lt;P&gt;We're not moving to the NIST standards, due to PCI DSS, which has old school style password complexity and aging requirements as part of the mandated compliance.&amp;nbsp; Instead we're simply encouraging users to select longer passwords when they expire.&amp;nbsp; Once we get to a position of having significantly reduced sign on, we'll be able to revisit.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 15:00:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31468#M2100</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2020-01-10T15:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31472#M2101</link>
      <description>&lt;P&gt;Thanks Craig.&amp;nbsp; I do understand all of the information you have kindly provided.&amp;nbsp; I am looking for specific advice for screening the newly created passwords to prevent extremely simple passwords from being used for even a short period of time.&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 16:38:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31472#M2101</guid>
      <dc:creator>apbanohit</dc:creator>
      <dc:date>2020-01-10T16:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31473#M2102</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1029517125"&gt;@apbanohit&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Thanks Craig.&amp;nbsp; I do understand all of the information you have kindly provided.&amp;nbsp; I am looking for specific advice for screening the newly created passwords to prevent extremely simple passwords from being used for even a short period of time.&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Tom,&lt;/P&gt;&lt;P&gt;OK.. got it. Excellent to be considering that side of the challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An easy way &amp;nbsp;to do that is to add a function to the password registration validity check that matches the proposed password against a master list of very poor passwords (e.g. password, 123456, P@ssw0rd, etc.) and if there is a match have a standard screen that rejects that one telling the user,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"You have selected a very common short password often easily guessed by intruders. Please change to a longer multi word passphrase as described in the full guidance."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are plenty of lists of common and easily compromised passwords you can use for this step.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 17:47:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31473#M2102</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2020-01-10T17:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31502#M2104</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;EM&gt;Please change to a longer multi word passphrase as described in the full guidance."&lt;/EM&gt;&lt;/BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Since implementing password phrases our organization has seen a spike in "post-it note" purchase requests. No kidding! To be secure some users are writing their passwords on the back to fool us. But we catch'em.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2020 03:52:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31502#M2104</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-01-11T03:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31504#M2105</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remember password I do." style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/3753i979019351C5DFDC7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="baby yoda password.jpg" alt="Remember password I do." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Remember password I do.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2020 03:57:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/31504#M2105</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-01-11T03:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/37427#M2857</link>
      <description>&lt;P&gt;If your organization would like to implement the new NIST Password recommendations, the need for PCI DSS compliance is not something standing in your way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an FAQ on the PCI SSC Web Site covering this situation. As the SSC points out, entities are allowed to implement alternative controls other than those specified in the standard as long as the intent of the PCI DSS requirements is met.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FAQ specifically mentions the NIST SP 800-63B alternative controls, and points out the importance of considering all of the recommendations as a complete set of controls, rather than looking at them in isolation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://pcissc.secure.force.com/faq/articles/Frequently_Asked_Question/Can-organizations-use-alternative-password-management-methods-to-meet-PCI-DSS-Requirement-8?q=nist&amp;amp;l=en_US&amp;amp;fs=Search&amp;amp;" target="_blank"&gt;Can organizations use alternative password management methods to meet PCI DSS Requirement 8?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To avoid the "post-it" problem, most organizations implementing the NIST guidance also provide the ability for users to manage those unique, strong passwords with an automated password manager that utilizes multi-factor authentication for access to the password wallet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 00:39:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/37427#M2857</guid>
      <dc:creator>jimscard</dc:creator>
      <dc:date>2020-07-19T00:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/38093#M2907</link>
      <description>&lt;P&gt;Does this also apply to privilege level Administrative Passwords?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 23:02:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/38093#M2907</guid>
      <dc:creator>rdaniels</dc:creator>
      <dc:date>2020-08-12T23:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/38096#M2908</link>
      <description>Hi,&lt;BR /&gt;Yes, the guidance applies to all user passwords, including those for administrators / elevated privilege users.&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Aug 2020 23:33:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/38096#M2908</guid>
      <dc:creator>jimscard</dc:creator>
      <dc:date>2020-08-12T23:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: NIST Password Standard</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/38542#M2931</link>
      <description>&lt;P&gt;Every countermeasure has it's own flaws and new vulnerabilities&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 08:50:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-Password-Standard/m-p/38542#M2931</guid>
      <dc:creator>mtissink</dc:creator>
      <dc:date>2020-08-28T08:50:53Z</dc:date>
    </item>
  </channel>
</rss>

