According to the UK government, the Cyber Essentials security controls can prevent around 80% of cyber-attacks. The controls are mandatory for all government contracts that involve handling personal information, and delivering certain information communications technology products.
This whitepaper explores the role of password policy and password security in achieving Cyber Essentials accreditation.
It focuses on five key areas vital to passing the scheme:
- Secure configuration and passwords
- Access control and passwords
- Account lockouts to defend against brute-force attacks
- Using a password blacklist
- Expiring passwords when necessary