Security Basics mailing list archives

A doable frequent password change policy?


From: WALI <hkhasgiwale () gmail com>
Date: Fri, 29 Jun 2007 09:20:42 +0400

Yes I am aware of the importance of advising users on changing their passwords frequently, be it their AD passwords or passwords on other independent applications (ERP) etc.

But I don't want to enforce a policy that comes crashing down. I personally, cannot keep changing my password every month making sure that it differs from the last two in history (at least).

Even Cisco on it's CCO account only makes it's users aware that their password hasn't been changed for quite some time and giving them an option of either changing it or just do a 'No Thanks' option and carry on with their old password. This sounds like a doable compliance to me.

Your thoughts??


Current thread: