1.1.1 Enforce password history (>=24)

Information

This control defines the number of unique passwords a user must leverage before a previously used password can be reused. If an attacker compromises a given credential that is then expired, this control prevents the user from reusing that same compromised credential.

Solution

Make sure 'Enforce password history' is set to remember a minimum of 24 passwords.

See Also

https://workbench.cisecurity.org/files/10

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-2237-6

Plugin: Windows

Control ID: 25aac58d937e10651526a119de5ca18e530f2a984213e8893d6c22540367f770