May 18, 2023, 5:17 p.m. | /u/_finack

cybersecurity www.reddit.com

As you likely know, NIST recommends against the practice of expiring user passwords after a period of time and instead only forcing password changes when there is compromise.

Has your organization actually ended the practice of expiring user passwords? If your organization hasn't, please consider sharing why not. If your organization did, consider sharing what other controls or strengthening your org did to go along with it.

[View Poll](https://www.reddit.com/poll/13l4wbe)

compromise cybersecurity expiration nist org organization password password expiration passwords period practice sharing

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Level 1 SOC Analyst

@ Telefonica Tech | Dublin, Ireland

Specialist, Database Security

@ OP Financial Group | Helsinki, FI

Senior Manager, Cyber Offensive Security

@ Edwards Lifesciences | Poland-Remote

Information System Security Officer

@ Booz Allen Hamilton | USA, AL, Huntsville (4200 Rideout Rd SW)

Senior Security Analyst - Protective Security (Open to remote across ANZ)

@ Canva | Sydney, Australia