- Contain both numeric and alphabetic characters.
- Users to change passwords at least every 90 days.
- Password parameters are set to require that new passwords cannot be the same as the four previously used passwords.
Which go against the NIST guidelines. So how do you do things that are considered "best practices" when people like PCI require you to do them wrong?