ministryofjustice / itpolicycontent

Draft and review content for MoJ IT Policy.
10 stars 14 forks source link

Adjust password standard to remove explicit requirement for complex passwords. #48

Closed warmanaMOJ closed 6 years ago

warmanaMOJ commented 6 years ago

Feedback was received, pointing out that NCSC guidance recommends avoiding a requirement for complex passwords. Further, having a suitable password block list, alerts on brute force attempts, a maximum tries lockout, and identification of attempted sign ins from unusual locations would all comply with the intent of the NCSC guidance while removing the need for complex passwords.

This issue will draft an updated version of the password standard, accordingly, for review purposes.

warmanaMOJ commented 6 years ago

Updates made, as follows:

  1. Remove explicit requirement for complex characters in passwords.
  2. Link to NCSC guidance on not requiring complex passwords.
  3. Add section on Blocking passwords.

Final draft visible here.

Changes reviewed and OK'd by Jennifer L. and Greg S.

Please may I request approval to publish?

cybersquirrel commented 6 years ago

Approved.

warmanaMOJ commented 6 years ago

Thank you. Published.