New

Password Complexity Requirements

Currently any user in sage including the admin can use the password "sage" or any other insecure combination of letters.
Can I request the ability to enforce password complexity as this is a requirement on Cyber Essentials Accreditation and ISO 27001

  • I'm not saying it is a valid reason, just pointing out that it's more of a tick box exercise to get a "get out of jail free" card for the enforcer1 that is actually likely to decrease security.

    1As the enforcer will say "I've enforced a specific security, therefore if someone has breached security using your credentials, it must be your fault"2.

    2One of the banks I use asks me every time a make a transfer3 to click "I agree to take the risk as I don't think it is a scam".  This is ridiculous as I regularly pay bills that way, and it becomes an automatic click-without-read Pavlovian response, just like the hated Vista User Account Control requiring far too much click-to-allow before anything much could be done.

    3Another of the banks I use came up with a "Are you sure this isn't a scan" warning when paying council tax, despite the bank in question actually giving me the council's bank details when I set up the payee; perhaps they knew more than the rest of us seeing as that council is now in financial troubles...

  • Nice spot, did not see that one but surely saying that people may white them down is not a valid reason to not implement the feature if it's a regulatory requirement?

  • See also: