Password expiration best practices?
February 27, 2006 11:16 AM Subscribe
Is there an "industry standard" for password expiration periods?
With the understanding that it depends on the "industry," and ultimately at the company/agency level, can a broad generalization be made that most corporate environments enforce {x}-day password expiration periods -- be it 30 days, 45 days, 60 days, 90 days, etc.? Is there a default starting point for IT security wonks?
There are some commonalities in password policies - longer than 8 characters, mixed characters, don't reuse old passwords, etc., but I've seen a huge range in expiration periods, all the way up to none.
Any security guys here who can point to some acronymed standards body or guideline with a number? Or will it always be, "it depends"?
posted by pzarquon to computers & internet (19 answers total) 1 user marked this as a favorite
posted by orthogonality at 11:24 AM on February 27, 2006