2 cissp ® Official Study Guide Eighth Edition


Creating Strong Passwords



Download 19,3 Mb.
Pdf ko'rish
bet550/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   546   547   548   549   550   551   552   553   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Creating Strong Passwords
Passwords are most effective when users create strong passwords. A strong password is suf-
ficiently long and uses multiple character types such as uppercase letters, lowercase letters, 
numbers, and special characters. Organizations often include a written 
password policy
in 
the overall security policy. IT security professionals then enforce the policy with technical 
controls such as a technical password policy that enforces the 
password restriction 
require-
ments. The following list includes some common password policy settings:
Maximum Age
This setting requires users to change their password periodically, such as 
every 45 days.


590
Chapter 13 

Managing Identity and Authentication
Password Complexity
The complexity of a password refers to how many character types it 
includes. An eight-character password using uppercase characters, lowercase characters, symbols, 
and numbers is much stronger than an eight-character password using only numbers. National 
Institute of Standards and Technology (NIST) special publication (SP) 800-63B, “Digital Identity 
Guidelines,” states that authentication systems should support the use of any printable American 
Standard Code for Information Interchange (ASCII) characters and the space character.
Password Length
The length is the number of characters in the password. Shorter pass-
words are easier to crack. As an example, a password cracker application running on a 
single computer can discover a complex five-character password in less than a second but 
it takes thousands of years to crack a complex 12-character password. Of course, different 
computers have different computing power, and it’s possible to create multiple computers
in a parallel processing system that can crack passwords much quicker. However, the point 
is that longer passwords are harder to crack than shorter passwords. NIST SP 800-63B 
states that passwords should be at least eight characters long, and systems should support 
passwords as long as 64 characters. Many organizations require privileged account pass-
words to be longer, such as at least 15 characters long.
Password length and Complexity recommendations
Passwords should be long, and the longer they are, the harder they are to discover. How-
ever, how long should a password be? It depends on who you ask. NIST SP 800-63B says 
that passwords should be at least eight characters long and support the use of any print-
able ASCII characters, and systems should support passwords of at least 64 characters 
long. It also recommends hashing the password using random salts of at least 32 bits in 
length and storing the salted hash of the password.
How long should passwords for privileged accounts be? That also depends on who you 
ask. NIST SP 800-63B indicates that if an account needs stronger protection, an additional 
authentication factor, such as a smart card (described later in this chapter), should be 
added. That’s not always possible, so many organizations choose to require privileged 
accounts to use longer passwords of 14 or 15 characters.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   546   547   548   549   550   551   552   553   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish