|
|
|
|
|
by funnybeam
696 days ago
|
|
I’ve had several companies, including cyber insurers, ask for specific password expiry policies and when I’ve gone back to them explaining that we don’t expire passwords and referencing the NCSC and NIST advice all of them have accepted that without any arguments. As you say, these are largely box ticking exercises but you don’t have to accept the limited options they give you as long as you can justify your position |
|