Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000154-IDPS-000143 | SRG-NET-000154-IDPS-000143 | SRG-NET-000154-IDPS-000143_rule | Medium |
Description |
---|
Authorization for access to any IDPS requires an approved and assigned individual account identifier. To ensure only the assigned individual is using the account, the account holder must create a strong password that is privately maintained and changed based on the organizationally defined frequency. A password must have an expiration date to limit the amount of time a compromised password can be used by a malicious user. |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43282_chk ) |
---|
View the password configuration for local accounts. Verify system is configured so the minimum time until a password can be reused is set to "1" or greater. If the value for the minimum time until a password can be reused is not set to "1" or greater, this is a finding. |
Fix Text (F-43282_fix) |
---|
Configure accounts (user or system) to enforce a minimum time until a password can be reused to "1" or greater. |