UCF STIG Viewer Logo

Maximum password/passcode age must be set as required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-25009 WIR-MOS-PDA-013 SV-31263r1_rule ECWN-1 IAIA-1 Low
Description
If the passcode is not changed periodically, then an adversary with knowledge of the passcode can use it indefinitely without detection, potentially allowing access to sensitive DoD information and enabling subsequent attacks.
STIG Date
PDA Security Technical Implementation Guide (STIG) 2013-03-14

Details

Check Text ( C-31671r1_chk )
Check a sample (3-4 devices) of site PDAs and verify the password age is set to 90 days or less.
Fix Text (F-27659r3_fix)
Set maximum passcode age to 120 days or less if the DAA requires this setting.