I am currently working on a project in which we are creating a large public website for my organization. This site will allow customers to register and register to receive confidential personal information.
From experience I know some basics, such as requiring a complex password and requiring an email address for the reset password used.
Basically what I'm looking for is some kind of well-documented recommendation or standards (like NIST or ISO) for these requirements.
I need to introduce this to a higher level director who insists on us:
If I can introduce some industry standard on why these are such risks, this will really help.
, Pointy-Haired ( , , , ), :
,
.
, , , SSN
- , SSN, - , . , , ( ), . , - ?
, reset PW.
LOL! -, , ( )? , . . ( ) ( )? , . , . , , .
, , , 3 4- ( , , )
, ( ), , . , .
, , . -, (.. ), .
, , , , , -, ? .
, , :
OWasp , , , , , , .
W3C bumf. , . WASC .
Source: https://habr.com/ru/post/1720087/More articles:How to replace the value of the * all * attribute with appropriate elements using XQuery? - xqueryThe difference between a variable length argument and function overloading is c ++Open GL - Overkill for the 2nd card game? - objective-chow to install haskell openid package in windows - windowsWhat are the other modern, free analogies of Squeak and Esterel? - cgot ORA-01843 when I try to insert date and time in Oracle - c #AppEngine Taskqueue: is there a way to determine the depth of the queue? - google-app-engineT-SQL query on huge table is slow depending on join conditions - sqlHuge EAR Deployment - java-eeHow to prevent the error list window from appearing in Visual Studio ASP.NET Editor? - editorAll Articles