5.4.1.5 Ensure all users last password change date is in the past

Information

All users should have a password change date in the past.

Rationale:

If a users recorded password change date is in the future then they could bypass any set
password expiration.

Solution

Investigate any users with a password change date in the future and correct them. Locking
the account, expiring the password, or resetting the password manually may be
appropriate.

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv6|16, CSCv7|4.4

Plugin: Unix

Control ID: 5e3bb6c46e31e8671dbeea8cad9d2fea9cec6033003e645fe5fd5c7087be1c8f