The National Institute of Standards and Technology (NIST) has released guidelines for implementing password policies that take human behavior into account. The guidelines, outlined in NIST Special Publication 800-63B, section 5.1.1.2, include the following best practices:
- Use your directory service to enforce basic password guidelines.
- Set human-friendly password policies.
- Help your users help themselves by providing resources and tools to create strong passwords.
- Ban commonly-used, expected, or compromised passwords.
- Establish essential security controls.
- Simplify NIST password guidelines with SpyCloud.
By implementing these best practices, organizations can improve their password security and reduce the risk of cyber attacks.