Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000163-RTR-NA | SRG-NET-000163-RTR-NA | SRG-NET-000163-RTR-NA_rule | Medium |
Description |
---|
Authorization for access to any network element requires an approved and assigned individual account identifier. To ensure only the assigned individual is using the account, the account holder must create a strong password that is privately maintained and changed based on the organization defined frequency. Password strength is a measure of the effectiveness of a password in resisting guessing, dictionary attacks, as well as, brute-force attacks. A password must have an expiration date to limit the amount of time a compromised password can be used by a malicious user. This requirement is applicable to network device management and is not applicable to the routing function. |
STIG | Date |
---|---|
Router Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000163-RTR-NA_chk ) |
---|
This requirement is NA for router. |
Fix Text (F-SRG-NET-000163-RTR-NA_fix) |
---|
This requirement is NA for router. |