Question: An information systems owner has decided to create a more stringent password policy based on recent reports that systems are being compromised with current user
An information systems owner has decided to create a more stringent password policy based on recent reports that systems are being compromised with current user credentials. The current policy has password complexity, reuse, and history measures in place; however, attackers are repeatedly gaining access to the systems after passwords have been changed. Which of the following would be the BEST method to add to the password policy to prevent compromise?
- Password recovery
- Account expiration
- Password length
- Account lockout
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
