Password Complexity
What is Password Complexity?
Requirements for password composition including minimum length, character variety, and prohibition of common or previously used passwords.
Terms that appear alongside password complexity
Each of these is named in at least one of the same controls as password complexity. The number is how many controls name both.
- authentication 6 shared controls
- access control 4 shared controls
- nist 4 shared controls
- saml 3 shared controls
- audit 3 shared controls
- policy 3 shared controls
- role based access control 2 shared controls
- oauth 2 shared controls
Frameworks that govern password complexity
What the standards actually require on password complexity
Requirements naming password complexity across 6 standards, quoted from the control text.
Set a minimum complexity for passwords, and require that a newly created password differ in its characters from the one it replaces.
IA.L2-3.5.7 · Password Complexity →Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.
IA-5(1) · Password-Based Authentication →Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.
IA-5(1) · Password-Based Authentication →Section 5.1 establishes electronic access account management capabilities required of IEDs. Per public IEEE 1686 + IEEE Std abstract + vendor capability statements (full IEEE text NOT reproduced): individual user accounts with unique identification (5.1) + no...
IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote · IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →The Privacy Protection (Data Security) Regulations 5777-2017 (Takhanot Hagannat Hapratiyot - Avtahat Meidah) supplement the 1981 Law with detailed technical and organisational security requirements + graduated by Security Level Classification (Basic/Medium/Hig...
IsraelPPL-DataSecurity-Regulations2017-ISO-CISO-Access-Logging-Backup-Physical-Removable-Annual-Audit · Israel POPL Data Security Regulations 5777-2017 + ISO Information Security Officer + Access Control + Logging + Backup + Physical Security + Removable Media + Risk Assessment + Penetration Testing + Annual Internal Audit + Amendment 13 Cyber Updates →Questions people ask about password complexity
What is Password Complexity?
Why is Password Complexity important for compliance?
Which compliance frameworks address Password Complexity?
Where can I learn more about Password Complexity?
See how Password Complexity applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.