Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

A doable frequent password change policy?

Subject: A doable frequent password change policy?
Date: Fri, 29 Jun 2007 09:20:42 +0400
Yes I am aware of the importance of advising users on changing their passwords frequently, be it their AD passwords or passwords on other independent applications (ERP) etc.

But I don't want to enforce a policy that comes crashing down. I personally, cannot keep changing my password every month making sure that it differs from the last two in history (at least).

Even Cisco on it's CCO account only makes it's users aware that their password hasn't been changed for quite some time and giving them an option of either changing it or just do a 'No Thanks' option and carry on with their old password. This sounds like a doable compliance to me.

Your thoughts??

<Prev in Thread] Current Thread [Next in Thread>
  • A doable frequent password change policy?, WALI <=