PCI Requirement 8.2.3 – Passwords Require a Min. of Seven Characters and Contain Numbers & Letters

preview_player
Показать описание

Passwords/passphrases are your organization’s first line of defense, which is why PCI Requirement 8.2.3 states that your users’ passwords/passphrases must require a minimum of seven characters and contain both numeric and alphabetic characters. The combination of length and alphanumeric characters gives passwords/passphrases the complexity and strength to stand against attackers. The PCI DSS explains, “Malicious individuals will often first try to find accounts with weak or nonexistent passwords. If passwords are short or simple to guess, it is relatively easy for a malicious individual to find these weak accounts and compromise a network under the guise of a valid user ID.”
Although PCI Requirement 8.2.3 asks that passwords/passphrases must require a minimum of seven characters and contain both numeric and alphabetic characters, sometimes due to technical limitations, these minimum requirements cannot be met. In these cases, passwords/passphrases must have complexity and strength at least equivalent to the parameters specified by PCI Requirement 8.2.3.
Stay Connected

More Free Resources

About Us
KirkpatrickPrice is a licensed CPA firm, PCI QSA, and a HITRUST CSF Assessor, registered with the PCAOB, providing assurance services to over 600 clients in more than 48 states, Canada, Asia, and Europe. The firm has over 12 years of experience in information security and compliance assurance by performing assessments, audits, and tests that strengthen information security and internal controls. KirkpatrickPrice most commonly provides advice on SOC 1, SOC 2, HIPAA, HITRUST CSF, PCI DSS, ISO 27001, FISMA, and CFPB frameworks.

Рекомендации по теме