Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000158-IDPS-000141 | SRG-NET-000158-IDPS-000141 | SRG-NET-000158-IDPS-000141_rule | Medium |
Description |
---|
Authorization for access to any IDPS requires an approved and assigned individual account identifier. To ensure only the assigned individual is using the account, the account holder must create a strong password that is privately maintained and changed based on the organizationally defined frequency. Password strength is a measure of the effectiveness of a password in resisting guessing, dictionary attacks, as well as, brute-force attacks. Combination of upper case, lower case, numbers, and special characters enhances the complexity of the password string. Use of a complex password helps to increase the time and resources required to compromise the password. |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43280_chk ) |
---|
View the password configuration for local accounts. Verify passwords are set to require one each of the following: upper case letters, lower case letters, numbers, and special characters. If passwords do not have one of each of the following: upper case letters, lower case letters, numbers, and special characters, this is a finding. |
Fix Text (F-43280_fix) |
---|
Configure accounts (user or system) to use passwords meeting the DoD standards of a case sensitive character mix of upper case letters, lower case letters, numbers, and special characters, including at least one of each. |