Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think we have it for one of the ISO compliances, too.


The ISO 27xxx standards in Information Security don't tell you how to do it, they tell you how to formalise what you decided to do (and how it can be monitored, audited, etc.). So the reason your ISO compliance forces you to do password rotation is that some twit added "password rotation" to the policies you decided you were going to implement. New task: Find the relevant policy and revise it citing the modern NIST guidance. Extra credit: Go through other policies that get in your way, figure out why they're in there and either you'll be reconciled to this annoyance in your life or you can revise the policy to not be a problem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: