1.1.4 Minimum password length (>=12)

Information

This control defines the minimum number of characters a user password must contain. Enforcing a minimum password length helps protect against brute force and dictionary attacks.

Solution

Make sure 'Minimum password length' is set to a minimum of 8 characters.

See Also

https://workbench.cisecurity.org/files/10

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-2240-0

Plugin: Windows

Control ID: ee52bce30da3e16cc0d1c517b7b3e30a1d0defe359d17b9fd544e5ed1a40a4f0