Why do our forum passwords need to be reset every 3 months?

(At least, this is inference since I last set my password 3 months ago and upon logging in, I was asked to reset it again.)

Comments

2 comments

  • Comment author
    Chai Fungtammasan DNAnexus Team

    Most likely, it's part of security/compliance protocol (FedRAM) when the portal was setting up. This is obviously overkill for webboard, and we are reviewing if we really need this webboard and some other components in high security/compliance framework.

    0
  • Thanks. That makes sense. As an aside, it is kind of funny if FedRAMP requires this since the NIST itself recommends against requiring password cycling (See section 10.2.1 "Memorized Secrets" from https://pages.nist.gov/800-63-3/sp800-63b.html : "Do not require that memorized secrets be changed arbitrarily (e.g., periodically) unless there is a user request or evidence of authenticator compromise.")

    0

Please sign in to leave a comment.