Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Resource Library

Stay ahead, stay connected, and discover the future of IT with Sourcepass.

Untitled design (3)

Events & Webinars

Dive into a dynamic calendar of webinars and in-person gatherings designed to illuminate the latest in managed IT services, cybersecurity, and automation.

Untitled design (3)

 

The Sourcepass Story

Sourcepass aims to be different. It is owned and operated by technology, security, and managed services experts who are passionate about delivering an IT experience that clients love.

Untitled design (3)

The Sourcepass Experience

At Sourcepass, we’re rewriting the IT and cybersecurity experience by helping businesses focus on what they do best, while we deliver the infrastructure, insights, and innovation to help them thrive.

Untitled design (3)

 

NIST’s New Password Guidelines

 
NIST’s New Password Guidelines

The National Institute of Standards and Technology (NIST), the federal agency responsible for setting technology standards, has proposed significant changes to password policies. These changes include ending mandatory password resets, restricting the use of certain characters, and discontinuing security questions.

Creating strong, secure passwords and managing them effectively is one of the most challenging aspects of cybersecurity. This task becomes even more complicated with the password rules enforced by employers, federal agencies, and online service providers. 

NIST has published the second public draft of its updated Digital Identity Guidelines, known as SP 800-63-4. This comprehensive document outlines both the mandatory technical requirements and recommended best practices for authenticating digital identities. Any organization that deals with the federal government online must comply with these standards.

Key Changes in Password Policies

The following changes aim to simplify password management while enhancing security:

  1. Elimination of Mandatory Password Resets: Users are no longer required to change their passwords periodically unless there is evidence of a security compromise.
  2. Character Composition Rules: Verifiers and credential service providers (CSPs) must not impose specific character composition rules, such as requiring a mix of character types.
  3. Password Length: Passwords must be at least eight characters long, with a recommendation of a minimum of 15 characters.
  4. Password Length Flexibility: Systems should allow passwords up to 64 characters in length.
  5. Character Inclusion: All printable ASCII characters, including spaces, should be allowed in passwords. Unicode characters are also permitted, with each character counted as one unit for password length purposes.
  6. Password Truncation: Password truncation is not allowed; the full password must be verified.
  7. Password Hints: Systems must not offer password hints accessible to unauthorized users.
  8. Knowledge-Based Authentication: The use of knowledge-based authentication methods, such as security questions, is discouraged.

These updates aim to simplify password management while enhancing security, making it easier for users to maintain strong, secure passwords without unnecessary complexity.

Want to Learn How Sourcepass Can Help You with Compliance?

With expert guidance and deep technical expertise, Sourcepass can help ensure data security and mitigate legal and financial risks, helping clients avoid penalties and protect sensitive information. 

Contact Sourcepass today to learn more about how our comprehensive cybersecurity services can help safeguard your business.