What's Your Password ft. Bryon Singh, RailWorks Corporation

What's Your Password ft. Bryon Singh, RailWorks Corporation

By Steve Gold
Posted in Security
On September 13, 2023

If you’ve ever seen Jimmy Kimmel Live, I hope you’ve seen the “What’s your Password” skit. As funny, and as incredibly disappointing this is, it’s real life. We’re not in Kansas anymore folks. Many years ago, all we needed to do to protect our assets was lock our door. Now, our assets are spread across a virtual kingdom.

Our online activities touch almost every aspect of our lives. From banking and shopping to work and communication, our digital presence is widespread. It's crucial to understand the importance of safeguarding your personal and professional accounts. One of the simplest yet most effective ways to do this is by using unique passwords for all your online activities.

By using unique passwords, understanding the power of password length, and the benefits of multi-factor authentication (MFA), you're creating an extra layer of defense against potential threats. Just as you wouldn't hand out copies of your house keys to strangers, avoid using the same password across multiple accounts.

This isn't solely an enterprise concern. If you recycle passwords and a breach occurs, attackers could potentially access your other accounts using that same password. Always opt for distinct passwords and ensure you update any default ones.

Effective password policies are pivotal in safeguarding organizational data. When incorporating MFA into the security infrastructure, enterprises can afford some flexibility in password requirements given the added layer of security MFA provides. However, for accounts without MFA, stricter password policies are crucial. Here's a suggested framework:

  1. For Users With MFA:
    1. Password Length: Minimum of 8 characters.
    2. Password Complexity: Should include at least one uppercase letter, one lowercase letter, one number, and one special character. Passwords with consecutive repeated characters should be avoided.
    3. Password Rotation: Change every 180 days, with reminders sent starting 15 days prior.
    4. Password History: Retain the last 5 passwords to prevent reuse.
    5. Account Lockout: After 5 failed login attempts, accounts should be locked out for 15 minutes or until admin intervention.
    6. Recovery Options: Ensure recovery options are linked to MFA, such as a code sent to a registered mobile number.
  2. For Users Without MFA:
    1. Password Length: Minimum of 14 characters.
    2. Password Complexity: Must include at least one uppercase letter, one lowercase letter, one number, two special characters, and avoid easily guessable words or combinations. No use of user's name, username, company name, or common words. Passwords with consecutive repeated characters should be avoided.
    3. Password Rotation: Change every 60 days, with reminders sent starting at 10 days prior.
    4. Password History: Retain the last 10 passwords to prevent reuse.
    5. Account Lockout: After 3 failed login attempts, accounts should be locked out for 30 minutes or until admin intervention.
    6. Recovery Options: Recovery options must be stringent, incorporating security questions, and possibly an additional verification method like email verification.

Here’s a link to an Account and Credential Management Policy Template provided free of charge from the fine folks at the Center for Internet Security: https://www.cisecurity.org/insights/white-papers/account-and-credential-management-policy-template-for-cis-controls-5-and-6

Here’s some details on this specific Control/Safeguard. If you want more detail, DM me.

CIS Control 5 – Account Management

Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.

Implementation Group 1

CIS Safeguard 5.2 - Use Unique Passwords

Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using MFA and a 14-character password for accounts not using MFA.

Steve Gold

Steve Gold

Steve Gold is the Cybersecurity Practice Director at Gotham Technology Group (Gotham). He is responsible for providing the vision and thought leadership to expand Gotham’s legacy of success and build a world-class cybersecurity practice. He works closely with Gotham’s customers, industry partners, and subject matter experts to develop relevant solutions for Gotham’s clients and prospects.

Prior to joining Gotham, Steve worked with the Center for Internet Security (CIS), where he expanded the global reach, revenue, and impact of the CIS Benchmarks, CIS Controls, and CIS Hardened Images. He led the efforts to promote the CIS portfolio of low-cost and no-cost cybersecurity products and services that help private and public organizations stay secure in the connected world. He grew a team of security specialists from 12 to over 40 to assist organizations with implementing security best practices in their continual journey of cybersecurity maturity.

During his more than 20-year career, Steve led teams responsible for developing and implementing technology solutions at some of the industry’s most recognized companies such as Varonis, VMware, Dell & Wyse Technology

Steve is a frequent speaker/moderator at industry conferences and webinars, covering a wide array of information security topics. He resides and works remotely in Baltimore, MD.