Skip to content

Module 5 Overview ​

February 8-14 · Reading: 10 pages plus NIST §3 · Estimated total: 6 hours

Three words get used as if they meant the same thing:

  • Identification: you claim to be somebody. Typing a username.
  • Authentication: you provide evidence for the claim. Typing the password.
  • Authorization: the system decides what that identity may do. Next week.

This week is the middle one. It is also the week with the largest gap between what most organizations do and what the current guidance says, because NIST changed its recommendations in 2017 and again in 2025, and a great many password policies have not caught up.

Learning Objectives ​

By the end of this week, the successful student will be able to:

  • 5.1: Select authentication factors appropriate to a stated threat model and justify the choice.
  • 5.2: Evaluate a real password and MFA policy against NIST SP 800-63B-4.

Assignments and Tasks ​

Due by Thursday at 11:59 p.m. Mountain Time ​

Due by Sunday at 11:59 p.m. Mountain Time ​

Run password_demo.py before posting to D3: part 3 asks you to quote two numbers from your own run.

Time Estimate ​

ActivityTime
Reading (10 pages plus NIST §3)1 hr 55 min
The notes page and running password_demo.py40 min
D3 post and two replies1 hr 5 min
Review and slack2 hrs 30 min
Total~6 hrs

Released under the MIT License.