1.1.3 Minimum password age (>=1)

Information

This control defines how many days a user must use the same password before it can be changed. This control should be configured to at least 1 day so a user cannot keep changing his password in order to clear the cache to use the same original password.

Solution

Make sure 'Minimum password age' is set to a minumum of 1 day.

See Also

https://workbench.cisecurity.org/files/10

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-1861-4

Plugin: Windows

Control ID: c927547937dd8a54be1ead2d0ae4b7abd6a1d28e6ab6313cf9cac138b5d4c92d