A security administrator at a global organization wants to update password complexity rules for a system containing personally identifiable information. Which of the following would be the best resource for this information?
Correct Answer: A
Step by Step Explanation:
NIST (National Institute of Standards and Technology): Provides comprehensive password guidelines (e.g., SP 800-63B) widely used for securing systems, including handling PII.
GDPR (General Data Protection Regulation): Focuses on data privacy laws rather than technical password policies.
CMMI (Capability Maturity Model Integration): Addresses process improvement, not password complexity.
COPPA (Children's Online Privacy Protection Act): Focuses on child data privacy, not password rules.
Reference: CASP+ Exam Objectives 5.3 - Implement security controls and best practices using NIST standards.