Back to category

Week 13

Evaluate Password Policy Against Industry Baseline

Intermediate
GRC Analyst
CIS Benchmarks
CIS Controls v8
NIST SP 800-63B
Policy Review
Authentication Controls Assessment
Gap Analysis
Phishing-Resistant MFA
Passwordless Adoption

Client Background

Harbor View Legal Group is a mid-sized law firm handling sensitive client case files, including privileged communications and financial records for corporate clients. The firm has never had its password policy formally reviewed.

Business Environment

A malpractice insurance renewal questionnaire asked whether the firm's password policy meets 'industry standard baselines,' a question the managing partner could not answer, prompting this review before the renewal deadline.

Security Incident

No breach has occurred; the engagement is a proactive baseline review. A peer law firm recently suffered a credential-stuffing breach traced to a weak shared password and a social-engineered helpdesk reset, and Harbor View's malpractice insurer now requires evidence that the firm's authentication policy meets current industry baselines before renewal.

Scope

Documentation review of the firm's written authentication policy, Active Directory / Microsoft Entra ID authentication settings export, helpdesk reset and verification procedures, MFA method inventory, and passwordless roadmap status. Excludes live penetration testing of authentication systems.

Objectives

  • Benchmark the firm's written authentication policy against current NIST SP 800-63B and CIS Benchmark guidance.
  • Assess enforcement of length-based requirements, breached-credential screening, and removal of forced rotation.
  • Evaluate MFA maturity, prioritizing phishing-resistant methods (FIDO2 security keys and passkeys).
  • Review passwordless adoption paths and identity threat detection and response (ITDR) coverage.
  • Assess helpdesk reset and account-recovery procedures for phishing-resistance.
  • Produce a Gap Report with a prioritized modernization roadmap.

Required Deliverables

Authentication Policy Gap Report
Modernization Roadmap
3 hrs estimated