CYB-16 · Cyber security
Password policy must enforce: minimum 12 characters, complexity requirements, and prohibition of reuse (last 12 passwords). Ideally aligned to NIST SP800-63b (length over complexity). Leaked credential monitoring must be in place to identify staff credentials that have appeared in data breach databases.
Trigger
Password policy below 8 characters; no complexity requirements enforced; no password history restriction; no breach credential monitoring in place
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Update password policy to minimum 12 characters, complexity enforced, last 12 passwords prohibited. Implement Have I Been Pwned (HIBP) integration or equivalent for breach credential alerts. Consider passphrase guidance for staff.
Evidence required