UCF STIG Viewer Logo

Administrator passwords must be changed as required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-14225 3.122 SV-24999r2_rule Medium
Description
The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the passwords. Passwords for the built-in administrator account and any emergency administrator accounts must be changed at least annually or when any member of the administrative team leaves the organization.
STIG Date
Windows 7 Security Technical Implementation Guide 2018-02-12

Details

Check Text ( C-62085r1_chk )
Determine if the site has a policy that requires passwords for the built-in administrator account and any emergency administrator accounts to be changed at least annually or when any member of the administrative team leaves the organization. If a policy does not exist or is not enforced, this is a finding.
Fix Text (F-66983r1_fix)
Define and enforce a policy that requires passwords for the built-in administrator account and any emergency administrator accounts to be changed at least annually or when any member of the administrative team leaves the organization.