Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-25009 | WIR-MOS-PDA-013 | SV-31263r1_rule | ECWN-1 IAIA-1 | Low |
Description |
---|
If the passcode is not changed periodically, then an adversary with knowledge of the passcode can use it indefinitely without detection, potentially allowing access to sensitive DoD information and enabling subsequent attacks. |
STIG | Date |
---|---|
PDA Security Technical Implementation Guide (STIG) | 2013-03-14 |
Check Text ( C-31671r1_chk ) |
---|
Check a sample (3-4 devices) of site PDAs and verify the password age is set to 90 days or less. |
Fix Text (F-27659r3_fix) |
---|
Set maximum passcode age to 120 days or less if the DAA requires this setting. |