Measuring NIST Authentication Standards Compliance by Higher Education Institutions

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Apthorpe, Noah, Beavers, Boen, Shvartzshnaider, Yan, Frischmann, Brett
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916786224496640
author Apthorpe, Noah
Beavers, Boen
Shvartzshnaider, Yan
Frischmann, Brett
author_facet Apthorpe, Noah
Beavers, Boen
Shvartzshnaider, Yan
Frischmann, Brett
contents Technical standards are a longstanding method of communicating best practice recommendations based on expert consensus. Cybersecurity standards are particularly important for informing policies that protect critical systems and sensitive data. Measuring standards compliance is therefore essential to identify vulnerabilities arising from outdated policies and to determine whether expert advice has effectively diffused to practitioners. In this paper, we examine the authentication policies of a diverse set of 135 colleges and universities in the United States and Canada to determine compliance with four standards from NIST Special Publication 800-63 Digital Identity Guidelines. We find widespread, but not universal, deployment of multi-factor authentication across institutions. We also find prevalent outdated use of password expiration, password composition rules, and knowledge-based authentication. These results support further investment and research into incentive structures for standards compliance and the diffusion of expert guidance to practitioners.
format Preprint
id arxiv_https___arxiv_org_abs_2409_00546
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Measuring NIST Authentication Standards Compliance by Higher Education Institutions
Apthorpe, Noah
Beavers, Boen
Shvartzshnaider, Yan
Frischmann, Brett
Cryptography and Security
Computers and Society
Technical standards are a longstanding method of communicating best practice recommendations based on expert consensus. Cybersecurity standards are particularly important for informing policies that protect critical systems and sensitive data. Measuring standards compliance is therefore essential to identify vulnerabilities arising from outdated policies and to determine whether expert advice has effectively diffused to practitioners. In this paper, we examine the authentication policies of a diverse set of 135 colleges and universities in the United States and Canada to determine compliance with four standards from NIST Special Publication 800-63 Digital Identity Guidelines. We find widespread, but not universal, deployment of multi-factor authentication across institutions. We also find prevalent outdated use of password expiration, password composition rules, and knowledge-based authentication. These results support further investment and research into incentive structures for standards compliance and the diffusion of expert guidance to practitioners.
title Measuring NIST Authentication Standards Compliance by Higher Education Institutions
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2409.00546