
Week 13
Evaluate Password Policy Against Industry Baseline
Client Background
Harbor View Legal Group is a mid-sized law firm handling sensitive client case files, including privileged communications and financial records for corporate clients. The firm has never had its password policy formally reviewed.
Business Environment
A malpractice insurance renewal questionnaire asked whether the firm's password policy meets 'industry standard baselines,' a question the managing partner could not answer, prompting this review before the renewal deadline.
Security Incident
No breach has occurred; the engagement is a proactive baseline review. A peer law firm recently suffered a credential-stuffing breach traced to a weak shared password and a social-engineered helpdesk reset, and Harbor View's malpractice insurer now requires evidence that the firm's authentication policy meets current industry baselines before renewal.
Scope
Documentation review of the firm's written authentication policy, Active Directory / Microsoft Entra ID authentication settings export, helpdesk reset and verification procedures, MFA method inventory, and passwordless roadmap status. Excludes live penetration testing of authentication systems.
Objectives
- Benchmark the firm's written authentication policy against current NIST SP 800-63B and CIS Benchmark guidance.
- Assess enforcement of length-based requirements, breached-credential screening, and removal of forced rotation.
- Evaluate MFA maturity, prioritizing phishing-resistant methods (FIDO2 security keys and passkeys).
- Review passwordless adoption paths and identity threat detection and response (ITDR) coverage.
- Assess helpdesk reset and account-recovery procedures for phishing-resistance.
- Produce a Gap Report with a prioritized modernization roadmap.
Required Deliverables