"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
-NIST Digital Identity Guidelines Section 5.1.1.2
Yet I cannot escape IT departments insisting upon it. Every time it happens I want to send them a "cybersecurity training module" right back at them.
https://pages.nist.gov/800-63-3/sp800-63b.html
#cybersecurity