Body
The password complexity rules for accounts at Northeast are as follows:
- Limit repeated access attempts by locking out the user ID after not more than six attempts.
- Set the lockout duration to a minimum of 30 minutes or until an administrator enables the user ID.
- Passwords/passphrases must meet the following:
- Require a minimum length of at least twelve characters, maximum of 20.
- Password must contain at least one uppercase letter, lowercase letter, number, and a special character.
- Disallow First Name, Last Name and Username in the password when possible
- Change user passwords/passphrases at least once every 90 days.
- Do not allow an individual to submit a new password/passphrase that is the same as any of the last four passwords/passphrases they used.