Password policy

The rules an organisation sets for choosing, checking, storing and changing passwords. Current NIST guidance favours length and blocklist screening over complexity rules and forced expiry.

A password policy is the set of rules that governs how passwords are chosen, checked, stored and changed across an organisation’s systems. The current reference point is NIST SP 800-63B-4 (July 2025), sections 3.1.1.1 and 3.1.1.2. It sets a minimum length (15 characters where the password is the only factor, 8 where it is part of multi-factor authentication), requires new passwords to be screened against a blocklist of commonly used, expected or compromised values, and requires rate limiting of failed attempts. It forbids other composition rules, such as a required mix of character types, and forbids forced periodic change unless there is evidence of compromise.

Older study material, and some organisations’ policies, still carry complexity rules and fixed expiry. Users tend to meet both with predictable patterns that attackers anticipate. A policy also commonly covers throttling or account lockout and how resets are verified. The same NIST guidance states that passwords are not phishing-resistant, so a strict policy is not a substitute for multi-factor authentication, and a blocklist is one of the defences against a dictionary attack.

Exam relevance: questions in this area tend to set the current NIST position against older habits. Candidates are expected to know both positions and where each comes from, rather than assume that complexity and 90-day expiry are best practice.