5.2.7 Password Age

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Over time passwords can be captured by third parties through mistakes, phishing attacks, third party breaches or merely brute force attacks. To reduce the risk of exposure and to decrease the incentives of password reuse (passwords that are not forced to be changed periodically generally are not ever changed) users should reset passwords periodically.
This control uses 365 days as the acceptable value, some organizations may be more or less restrictive. This control mainly exists to mitigate against password reuse of the macOS account password in other realms that may be more prone to compromise. Attackers take advantage of exposed information to attack other accounts.

Rationale:

Passwords should be changed periodically to reduce exposure

Solution

Perform the following to implement the prescribed state for all pwpolicy controls

Run the following command in Terminal:

pwpolicy -setaccountpolicies

Examples in pwpolicy man page

See Also

https://workbench.cisecurity.org/files/2112

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)

Plugin: Unix

Control ID: 380bb972ecb6864f8c3031735bd471898aa1aba88df51c86a979182d8ad29163