Password testing seems simple, but many nuances can trip up an auditor. In this session, we discuss how to test passwords based on the standards in FISCAM and NIST. We present real examples from the field for each test.
This course is a part of IT Audit Bytes series. The other Segments of this series are:
- IT Audit Bytes - Access Control
- IT Audit Bytes - Backup and Recovery
- IT Audit Bytes - Change Management
- IT Audit Bytes - Cybersecurity
- IT Audit Bytes - Data Loss Prevention
- IT Audit Bytes - Disaster Recovery and BCP
- IT Audit Bytes - IT Control Frameworks/li>
- IT Audit Bytes - Job Monitoring
- IT Audit Bytes - Logging and SEIM
- IT Audit Bytes - Network Security and Detection
- IT Audit Bytes - Password Management
- IT Audit Bytes - Physical Security
- IT Audit Bytes - Provisioning and Deprovisioning
- IT Audit Bytes - SDLC Controls
- IT Audit Bytes - Security Awareness Training
- IT Audit Bytes - Separation of Duties Controls
- IT Audit Bytes - SOC Reports
- IT Audit Bytes - Strategy and Governance
- IT Audit Bytes - Third-Party IT Risk Management (TPRM)
Prerequisites
No advanced preparation or prerequisites are required for this course.
Learning Objective
- Identify the major elements of password controls.
- Discover and describe how to perform tests for password controls.
- Recognize problems that can trip up an auditor.
Last updated/reviewed: March 15, 2025
(0) Reviews
(0 rating)Lesson Questions and Answers0 Questions
Progress
INTRODUCTION AND OVERVIEW
- Introduction to Passwords Management 1:02
- Federal Information System Controls Audit Manual 9:08
- Control Testing 16:06
CONTINUOUS PLAY
SUPPORTING MATERIAL
REVIEW & TEST
- REVIEW QUESTIONS quiz
- FINAL EXAM exam
IT Audit Bytes - Password Management
Certified Public Accountant
Online
No advanced preparation or prerequisites are required for this course.

NASBA Sponsor Number: 109504
State of New York Sponsor Number: 002746
State of Texas Sponsor Number: 009890
Chartered Accountant (IES8 CPD)
Online
Certified Management Accountant
Online
No advanced preparation or prerequisites are required for this course.
Certified Fraud Examiner
Online
No advanced preparation or prerequisites are required for this course.
Certified Internal Auditor
Online
No advanced preparation or prerequisites are required for this course.

Recognized CPE provider, authorized by the Institute of Internal Auditors for use in the Certified Internal Auditor (CIA) CPE program.
Certification in Risk Management Assurance
Online
No advanced preparation or prerequisites are required for this course.

Recognized CPE provider, authorized by the Institute of Internal Auditors for use in the Certified Risk Management Assurance (CRMA) CPE program.
Ask the instructor a question about this lesson