Cyberstudy
PDF p.82 In progress

Password Concepts

Open PDF at p.82 16 flashcards

Summary

PDF p.82

Improper credential management is a major security risk. Organizations relying on password-based credentials must enforce strong policies and training. Key aspects include password best practices, credential management policies, and system-enforced account policies.

In plain words

Supplementary — not from your PDF

Weak password handling is one of the most common ways in. Organizations set password policies (length, history, reuse rules) and train people. Current NIST guidance favours longer passwords over complexity rules and forced regular changes.

Detailed explanation

PDF p.82
  • Credential Management
    • Importance: Poor management of credentials is a common attack vector.
    • Policies: Strong policies and training are essential for secure password usage.
  • Password Best Practices Policy
    • Purpose: Guides users on choosing and maintaining secure passwords.
    • Scope: Part of a broader credential management policy covering passwords, smart cards, and biometric IDs.
    • Awareness: Educates users on social engineering attacks like phishing and pharming.
  • System-Enforced Account Policies
    • Password Length: Sets minimum (and possibly maximum) password length.
    • Password Complexity: Requires a mix of uppercase, lowercase, alphanumeric, and non-alphanumeric characters.
    • Password Age: Forces periodic password changes.
    • Password Reuse and History: Prevents reuse of recent passwords and quick cycling through password changes.
  • Password Aging vs. Expiration
    • Aging: Allows login with the old password but requires immediate change.
    • Expiration: Disables login with the outdated password.
  • NIST Guidance
    • Update: Recent NIST guidelines deprecate traditional practices like complexity, aging, and password hints.
  • Password Reuse
    • Risk: Using work passwords on other sites increases security risks.
    • Mitigation: Soft policies can help discourage this behavior.

Important terms

taken from the text above
Policies
Strong policies and training are essential for secure password usage.
Awareness
Educates users on social engineering attacks like phishing and pharming.
Password Length
Sets minimum (and possibly maximum) password length.
Password Complexity
Requires a mix of uppercase, lowercase, alphanumeric, and non-alphanumeric characters.
Password Age
Forces periodic password changes.
Password Reuse and History
Prevents reuse of recent passwords and quick cycling through password changes.
Aging
Allows login with the old password but requires immediate change.
Expiration
Disables login with the outdated password.
Update
Recent NIST guidelines deprecate traditional practices like complexity, aging, and password hints.

Examples & real-world scenarios

Supplementary — not from your PDF
  • A minimum length of 14 characters.
  • Password history preventing reuse of the last 10 passwords.
  • Training staff not to reuse work passwords on other sites.

Scenario

A policy forces a password change every 30 days, so users cycle Summer2025!, Autumn2025!. The policy made passwords predictable. Longer passphrases plus MFA would serve better.

Common mistakes

Supplementary — not from your PDF
  • Mixing up aging (you must change at next login) and expiration (the old password stops working).
  • Assuming complexity rules always help. NIST now deprecates them in favour of length and screening.

Practical skills

Supplementary — not from your PDF
  • Draft a modern password policy.

What I should remember

Key Points PDF p.82
  • Credential Management
    • Security Risk: Poor management is a common attack vector.
    • Policies and Training: Essential for secure usage.
  • Password Best Practices
    • Guidance: Choosing and maintaining secure passwords.
    • Social Engineering: Awareness of phishing and pharming.
  • System-Enforced Policies
    • Length: Minimum and maximum requirements.
    • Complexity: Mix of character types.
    • Age: Periodic changes.
    • Reuse and History: Prevents reuse and quick cycling.
  • Aging vs. Expiration
    • Aging: Immediate change after login.
    • Expiration: Disables outdated passwords.
  • NIST Guidelines
    • Deprecation: Traditional practices like complexity and aging.
  • Password Reuse
    • Risk: Using work passwords elsewhere.
    • Mitigation: Soft policies to discourage reuse.