UCF STIG Viewer Logo

Maximum password/passcode age must be set as required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-25009 WIR-MOS-PDA-013 SV-31263r2_rule ECWN-1 IAIA-1 Low
Description
If the passcode is not changed periodically, then an adversary with knowledge of the passcode can use it indefinitely without detection, potentially allowing access to sensitive DoD information and enabling subsequent attacks.
STIG Date
PDA/Smartphone Security Technical Implementation Guide 2011-10-07

Details

Check Text ( C-31671r1_chk )
Check a sample (3-4 devices) of site PDAs and verify the password age is set to 90 days or less.
Fix Text (F-27659r2_fix)
Set maximum passcode age as required.