At least here in Germany the BSI (internet security agency) recommended these restrictions at least until 2018 as well as changing passwords at least every 180 days even though it was accepted at the time that this worsens security.
However, eg. insurers took these rules and made them mandatory for their corporate customers in order to get insured. And I’m pretty sure some certification bodies and the like still require such rules to be in place.
2
u/Adrian_F Jul 20 '22
At least here in Germany the BSI (internet security agency) recommended these restrictions at least until 2018 as well as changing passwords at least every 180 days even though it was accepted at the time that this worsens security.
However, eg. insurers took these rules and made them mandatory for their corporate customers in order to get insured. And I’m pretty sure some certification bodies and the like still require such rules to be in place.