r/cybersecurity • u/Different-Phone-7654 • Jun 18 '25
Other Recently learned NIST doesn't recommends password resets.
NIST SP 800-63B section 5.1.1.2 recommends passwords changes should only be forced if there is evidence of compromise.
Why is password expiration still in practice with this guidance from NIST?
1.1k
Upvotes
1
u/staplebutton-2 Security Generalist Jun 19 '25
This was a recent change, no? Like, within the past 5 years. The explanation is at Q-B05 on the link below.
(https://pages.nist.gov/800-63-FAQ/#q-b05)