Almost as ~~bad~~ glorious as Breezewood, PA.
woodytrombone
joined 2 years ago
Yep, that's dumb. SOC2 is built upon NIST guidance, not the other way around.
If you have any voice with your Security department, you can tell them that rotating passwords are counter to NIST SP 800-63B (Section 10.2.1) guidance:
Do not require that memorized secrets be changed arbitrarily (e.g., periodically) unless there is a user request or evidence of authenticator compromise.
Though I haven't shot the FAMAS, 3-round burst fired from an M4 is clearly distinguishable from firing a single round (and alerts range safeties within a 300m radius)
I didn't order waffle fries!
(I usually see the Computer Fraud and Abuse Act abbreviated CFAA)