549
NIST proposes barring some of the most nonsensical password rules
(arstechnica.com)
This is a most excellent place for technology news and articles.
My argument is that if this document (and others) are requirements for companies shouldn't there also be a more approachable document for people to use?
Sure, have the jargon filled document that those in the know can access, but without an additional not so jargon-y document you've just added a barrier to change. Maybe just an abstract of the rule changes on the front page without the jargon?
I don't know, maybe it's not a big deal to compliance officers but just seems to me (someone that isn't a compliance officer) that obfuscating the required changes behind jargon and acronyms is going to slow adoption of the changes.
It needs to be specific to be clear for its purposes. You can express everything in simpler terms but then you risk leaving things out of definitions. It's basically legal speak.
Normally, you'd read the scope of such a document to see whether it fits your purpose, then cherry-pick the chapters necessary. If something's unclear, you can google pretty much everything.
Doing that a few times will make it infinitely easier! You especially get to understand those broad, inaccessible definitions a lot easier.