Hey B, have you heard about ISO 27001 Password Policy?

Yeah, I have. It's a set of guidelines for managing passwords, right?

Exactly! Do you think our company should implement it?

Well, it wouldn't hurt to have some best practices in place. What does ISO recommend?

They recommend using strong passwords and changing them regularly.

That sounds like common sense. Do they recommend anything else?

Yes, they recommend using multi-factor authentication and encrypting passwords.

Good to know. What about password length?

They recommend a minimum of 8 characters, but more is always better.

Agreed. And what about password complexity requirements?

ISO recommends using a combination of uppercase and lowercase letters, numbers, and symbols.

Oh boy, my password is just my dog's name...

Haha, time to change it up! But seriously, using personal information in passwords is a big no-no.

I know, I know. I'll get on it. So, any other recommendations we should consider?

Well, they also recommend having a password management policy in place and providing employee training on best practices.

Makes sense. Do you think our IT team has the resources to implement these recommendations?

I think so, but it wouldn't hurt to have a discussion with them about it.

Agreed. Thanks for bringing this to my attention, A.

No problem, B. It's always good to stay up-to-date on best practices for cybersecurity.