Educause Security Discussion mailing list archives

Re: NIST guidelines for passwords


From: Thomas Dugas <dugast () DUQ EDU>
Date: Tue, 13 Mar 2018 21:00:20 +0000

Chad,
We have not. Mainly because our auditors are still following the ISACA guidance that hasn't recognized the new NIST 
guidelines yet. We plan to keep working on them though and hopefully they update their guidelines as well. 

Tom Dugas
Director, Information Security/New Initiatives
Duquesne University


-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Chad 
Miller
Sent: Tuesday, March 13, 2018 3:29 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] NIST guidelines for passwords

Good afternoon,

I'm wondering if other schools have implemented the "new" NIST guidelines for passwords?  If you have, how were the new 
guidelines received by faculty/staff?  Do you have an associated policy that you would be willing to share?  Thanks!

Chad Miller
CIO UNWSP  

Current thread: