1.1.2 Maximum password age (Max of 90 days or less)

Information

This control defines how many days a user can use the same password before it expires. Having a shorter password age will decrease the chances of a brute force attack. A brute force attack is one where the attacker guesses every possible character combination by splitting password into smaller made from the original password.

Solution

Make sure 'Maximum password age' is set to a maximum of 90 days.

See Also

https://workbench.cisecurity.org/files/10

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-2200-4

Plugin: Windows

Control ID: e17b363196b6a6846ccc540e85627fcd374be74943848909f91a3ab9dee456c2