header image icon - block

NIST Password Best Practice Checklist

NIST Password Best Practice Checklist 33

NIST or National Institute of Standards and Technology has established itself as a authority figure for best practices on security and securing identities, password protection, and much more.

While developing new systems web application security is essential. 

Brief summary overview of 800-63 guidelines in a checklist. If you want to read the full guidelines NIST Special Publication 800-63 guidelines for 2019 

NIST Password Summary Checklist

NIST Password Best Practice Checklist 34

Characters

Support at least 64 characters maximum length including all ASCII characters within password.

Minimum characters: 8 when set by a human and 6 whencreated by a system.

NIST Password Best Practice Checklist 34

Avoid

Avoid  password hints and knowledge-based authentication like your first dog.

Avoid password expiration period

NIST Password Best Practice Checklist 34

LockOut

Allow a minimum of 10 password attempts before lockout

NIST Password Best Practice Checklist 34

No SMS for 2FA

No SMS for 2FA

Consider using an app like Google Authenticator.

NIST Password Best Practice Checklist 34

Password Dictionaries

Check password against known password dictionaries.

Related Checklists

Leave a Reply

Your email address will not be published. Required fields are marked *