An IS auditor is assessing the adequacy of password policies. Which finding represents the HIGHEST risk?
-
A
Passwords must be at least 8 characters long
-
B
Passwords do not expire for service accounts
-
C
Users are required to change passwords every 90 days
-
D
Password history prevents reuse of the last 10 passwords