5.2.7 Password Age

Information

Passwords should be changed periodically to reduce exposure

Solution

Perform the following to ensure the system is configured as prescribed:

1. Run the following command in Terminal:
pwpolicy -getaccountpolicies | egrep policyAttributeExpiresEveryNDays

2. Verify the value returned
<string>policyAttributeCurrentTime &gt; policyAttributeLastPasswordChangeTime + policyAttributeExpiresEveryNDays * 24 * 60 * 60</string>
<key>policyAttributeExpiresEveryNDays</key>

Should contain 90 or less

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(d)

Plugin: Unix

Control ID: 0c928585e2f2622eac87234ea1b56b3bb1864dd7374b1b4497e9b0c6378bdc4e