The first point would be gamechanging. Also used to do govt work. I'm sure everyone has stories. My takeaways. 1) Understand what people need -> AND LET THEM DO IT. 2) DO NOT ADD A SINGLE NEW THING with the IT / automation. If the old system doesn't have it DO NOT ADD IT. No 20 extra fields for demographics if you didn't track that before. That can be added later IF it's a MUST. If they would take away all various fi…
> The IT folks say that passwords have to change every 90 days This is explicitly not the NIST recommendation (the group in gov that sets some security standards), but the word is not getting out quickly.
The current IRS requirements are 90 day password changes. Ergo - many people write their passwords down in a text document next to the software launch icon.
What I don't get - if your computer is hacked, and you force people to write down their passwords on the computer being hacked, they will even more easily be able to access the systems you have access to.
Google seems to get this right. I have had same password for 20 years, if I login with a new device I use my MFA (no SMS). If I do a security sensitive op I need to login and do an MFA again (password reset etc). I imagine they actually monitor and rate limit bad login attempts etc. A 10 character password is really fine then in my view as an example.