back

by jasonpeacock·4y ago·view on hn ↗
We effectively have this now with PCI-DSS (requirements imposed by credit-card processing companies), and it sucks because of the bureaucracy involved in making any change.

It has take literally over a decade to relax the requirement for password rotation from 3mo to 1yr for employee accounts of companies that process CC payments, despite industry knowledge and formal studies saying that frequent password rotation was detrimental and useless.

Instead of defining the process, state the outcome you want and set penalties on failing to meet the outcome.

E.g. "don't have password leaks, or it will cost $1k per account paid directly to the account holder" (or your percent of gross, split among leaked accounts). Let companies implement those controls however they wish, as long as they are achieving the outcome and penalties are actually being applied.

I agree that failures need to have significant penalties, otherwise companies will decide that the penalty costs less than the prevention (which is true today) and minimize their investment in security.