Unlocking the Truth About Password Changes: Why It's Long Overdue to Reconsider Mandatory Resets for Your Users (2024)

For decades, it was common practice for organizations to require employees to change their passwords on a regular basis, typically every 60 or 90 days. However, the National Institute of Standards and Technology (NIST) revised its guidelines several years back and no longer recommends periodic password changes as an effective security measure.

NIST is a non-regulatory agency of the United States Department of Commerce that develops and promotes standards and guidelines to improve information security. In 2017, NIST released its password management guidelines, including several changes from previous recommendations. One of the most notable changes was eliminating the requirement for periodic password changes.

This may be old news to many of you, especially among cybersecurity professionals. Yet many organizations, perhaps unknowingly, persist with this practice.

The rationale behind this change is based on several factors. First, NIST recognizes that requiring users to change their passwords frequently can lead to password fatigue, resulting in users creating weak or easily guessable passwords. Users may resort to using simple patterns or predictable variations on their previous passwords - making them easier for attackers to crack - if forced to create a new password every 60 to 90 days.

Furthermore, the cost and inconvenience of frequent password changes can be significant. Whenever a user is required to change their password, they must remember a new password and update it across all the systems and applications they use. This can lead to frustration and decreased productivity, especially if the user must remember multiple passwords.

Another issue with frequent password changes is that they do not necessarily improve security. If a user's password has already been compromised, forcing them to change it regularly will not prevent an attacker from continuing to use that password. Instead, it can give the user a false sense of security, leading them to believe that their accounts are more secure than they are.

NIST recommends that organizations only require password changes in situations where there is evidence of a compromise or if there is suspicion that a password has been stolen or leaked. In these cases, a password reset can be an effective security measure. However, NIST advises that password resets should be accompanied by other security measures, such as two-factor authentication or an account lockout policy, to ensure that the user's account remains secure.

Instead of requiring frequent password changes, NIST recommends using long, complex, and unique passwords. Passwords should be at least eight characters long, preferably longer, and should include upper and lowercase letters, numbers, and special characters. Users should be encouraged to create passwords that are easy to remember but difficult for others to guess.

Another key recommendation from NIST is the use of password managers. These tools can help users create and manage strong, unique passwords for all their accounts. A password manager can also help users avoid password reuse, a common security risk. By using a different password for each account, users can reduce the impact of a data breach or password leak.

In addition to these recommendations, NIST also advises organizations to implement other security measures to protect user accounts, such as multi-factor authentication and account lockout policies. Multi-factor authentication requires users to provide additional proof of identity, such as a fingerprint or SMA passcode, in addition to their password. Account lockout policies can prevent attackers from brute-forcing their way into an account by locking it after several failed login attempts.

NIST's change in password management recommendations reflects a growing recognition in the cybersecurity community that frequent password changes may not be an effective security measure. Instead, organizations should promote using strong and unique passwords, the utilization of password managers, and implementing additional security measures to protect user accounts. By adopting these best practices, organizations can improve their security posture and reduce the risk of a data breach or password leak.

Unlocking the Truth About Password Changes: Why It's Long Overdue to Reconsider Mandatory Resets for Your Users (2024)
Top Articles
US Help Center
Video: Use Word on a mobile device
Foxy Roxxie Coomer
Arkansas Gazette Sudoku
Do you need a masters to work in private equity?
Songkick Detroit
Words From Cactusi
B67 Bus Time
REVIEW - Empire of Sin
People Portal Loma Linda
Hijab Hookup Trendy
Top tips for getting around Buenos Aires
800-695-2780
Jesus Calling Oct 27
Ou Class Nav
Xxn Abbreviation List 2023
NBA 2k23 MyTEAM guide: Every Trophy Case Agenda for all 30 teams
Hennens Chattanooga Dress Code
Indystar Obits
Little Caesars 92Nd And Pecos
Homeaccess.stopandshop
LCS Saturday: Both Phillies and Astros one game from World Series
Www.paystubportal.com/7-11 Login
Engineering Beauties Chapter 1
Beaufort 72 Hour
Random Bibleizer
Penn State Service Management
Gus Floribama Shore Drugs
The Latest: Trump addresses apparent assassination attempt on X
Metro By T Mobile Sign In
Baldur's Gate 3 Dislocated Shoulder
Rocksteady Steakhouse Menu
The Ride | Rotten Tomatoes
THE 10 BEST Yoga Retreats in Konstanz for September 2024
Jefferson Parish Dump Wall Blvd
Streameast.xy2
Today's Gas Price At Buc-Ee's
Kelly Ripa Necklace 2022
„Wir sind gut positioniert“
No Boundaries Pants For Men
Executive Lounge - Alle Informationen zu der Lounge | reisetopia Basics
Sallisaw Bin Store
2013 Honda Odyssey Serpentine Belt Diagram
John Wick: Kapitel 4 (2023)
Kaamel Hasaun Wikipedia
40X100 Barndominium Floor Plans With Shop
9294027542
Tito Jackson, member of beloved pop group the Jackson 5, dies at 70
1990 cold case: Who killed Cheryl Henry and Andy Atkinson on Lovers Lane in west Houston?
Mytmoclaim Tracking
Puss In Boots: The Last Wish Showtimes Near Valdosta Cinemas
What Is The Gcf Of 44J5K4 And 121J2K6
Latest Posts
Article information

Author: Arielle Torp

Last Updated:

Views: 5672

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Arielle Torp

Birthday: 1997-09-20

Address: 87313 Erdman Vista, North Dustinborough, WA 37563

Phone: +97216742823598

Job: Central Technology Officer

Hobby: Taekwondo, Macrame, Foreign language learning, Kite flying, Cooking, Skiing, Computer programming

Introduction: My name is Arielle Torp, I am a comfortable, kind, zealous, lovely, jolly, colorful, adventurous person who loves writing and wants to share my knowledge and understanding with you.