@@ -29,7 +29,7 @@ Applies to all GitLab team members, contractors, advisors, and contracted partie
Constructing secure passwords and ensuring proper password management is essential. GitLab's password standards are based, in part, on the recommendations by [NIST 800-63B](https://pages.nist.gov/800-63-3/sp800-63b.html). To learn what makes a password truly secure, read this [article](https://medium.com/peerio/how-to-build-a-billion-dollar-password-3d92568d9277) or watch this [conference presentation](https://www.youtube.com/watch?v=vudZnjp5Uq0&t=19183) on password strength.
**Note: If a system cannot support a specific configuration in this standard due to technical limitations, the configuration must be set to the closest possible setting that matches this standard. An exception must be opened [here](https://gitlab.com/gitlab-com/gl-security/security-assurance/governance-and-field-security/governance/exceptions-management), and an associated risk rating and exception review timeline will be assigned in accordance with the matrix in the request issue.**
**Note: If a system cannot support a specific configuration in this standard due to technical limitations, the configuration must be set to the closest possible setting that matches this standard. An exception must be opened [here](https://gitlab.com/gitlab-com/gl-security/security-assurance/governance-and-field-security/governance/security-governance), and an associated risk rating and exception review timeline will be assigned in accordance with the matrix in the request issue.**