Password strength and reuse restrictions are defined and enforced
Context and Guidance: Password strength and reuse requirements may not be supported by all assets within the function. Where feasible, these requirements may be informed by safety and operational considerations, the organisation's risk tolerance, the organisation's threat profile (THREAT-2e), asset priority, the sensitivity of information, or other considerations.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-1b, ACCESS-1d, ACCESS-1g, ACCESS-1h, ACCESS-1i.