Module 5 Overview
February 8-14 · Reading: 10 pages plus NIST §3 · Estimated total: 6 hours
Three words get used as if they meant the same thing:
- Identification: you claim to be somebody. Typing a username.
- Authentication: you provide evidence for the claim. Typing the password.
- Authorization: the system decides what that identity may do. Next week.
This week is the middle one. It is also the week with the largest gap between what most organizations do and what the current guidance says, because NIST changed its recommendations in 2017 and again in 2025, and a great many password policies have not caught up.
Learning Objectives
By the end of this week, the successful student will be able to:
- 5.1: Select authentication factors appropriate to a stated threat model and justify the choice.
- 5.2: Evaluate a real password and MFA policy against NIST SP 800-63B-4.
Assignments and Tasks
Due by Thursday at 11:59 p.m. Mountain Time
- Read 5.01 Readings and Lecture Notes and run
password_demo.py(2 hrs 35 min) - 5.02 D3: Authentication Policy Critique: initial post (45 min)
Due by Sunday at 11:59 p.m. Mountain Time
- 5.03 D3: Authentication Policy Critique - Replies: two replies (20 min, 30 points with the initial post)
Run password_demo.py before posting to D3: part 3 asks you to quote two numbers from your own run.
Time Estimate
| Activity | Time |
|---|---|
| Reading (10 pages plus NIST §3) | 1 hr 55 min |
The notes page and running password_demo.py | 40 min |
| D3 post and two replies | 1 hr 5 min |
| Review and slack | 2 hrs 30 min |
| Total | ~6 hrs |