CIS Password Policy Guide consolidates new password guidance into a single source. New password policy standards are based on two primary principles: leveraging real-world attack data and making it easier for users to create and remember passwords. The Guide was developed through the same community-driven, consensus-based process used to develop the CIS Benchmarks and CIS Controls. Use non-dictionary alternatives for passphrases, for example: Th3F0rdMust@ngis#1. Use MFA, sometimes referred to as Two-Factor Authentication (2FA)”]

