cisagov / ScubaGoggles

SCuBA Secure Configuration Baselines and assessment tool for Google Workspace
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
164 stars 22 forks source link

Updating Password Length Policy based on new NIST Guidelines #460

Closed mdueltgen closed 1 month ago

mdueltgen commented 1 month ago

πŸ—£ Description

[NIST's guidance] (https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver) is: "Verifiers and CSPs SHALL require passwords to be a minimum of eight characters in length and SHOULD require passwords to be a minimum of 15 characters in length." Based on internal discussion we are looking to adopt as split SHALL/SHOULD approach for the policy.

πŸ’­ Motivation and context

Closes #442

πŸ§ͺ Testing

βœ… Pre-approval checklist

βœ… Pre-merge Checklist

βœ… Post-merge Checklist

mdueltgen commented 1 month ago

@buidav I forgot about the drift rules, thanks for the reminder. Added them in.