1.1.1 Enforce password history (>=24)

Information

This control defines the number of unique passwords a user must leverage before a previously used password can be reused. If an attacker compromises a given credential that is then expired, this control prevents the user from reusing that same compromised credential.

Solution

Make sure 'Enforce password history' is set to remember a minimum of 24 passwords.

See Also

https://workbench.cisecurity.org/files/10

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-2237-6

Plugin: Windows

Control ID: ec7bfdf01eac0f54c9b3ab63b533c3d2bc94ed15b339b769bc22067f15a8a71b