WG060 - The web server application or system password is not changed at least annually.

Information

Vulnerability Key: V0002235
IA Controls: IAIA-1 Individual Identifitication and Authentication, IAIA-2 Individual Identification and Authentication
Categories: 1.1 Passwords
Severity: Category II
Ref: Chairman of the Joint Cheiefs of Staff Manual (CJCSM) 6510.01, Defense-in-Depth: Information Assuran
ENCLAVE SECURITY TECHNICAL IMPLEMENTATION GUIDE, WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.6
Normally, a service account is established for the web service to run under rather than permitting
it to run as system or root. The password on such accounts must be changed at least annually. It
is a fundamental tenet of security that passwords are not to be null and not to be set to never
expire. Finally, given the nature and proliferation of password cracking tools, the potential for a
malicious party to gain access to an atrophied web services account is significant.
Review the list of service accounts listed for the web server and ensure the passwords are changed annually.
For IIS or other web server installations that are running as localsystem, the password is changed automatically by the OS every 7 days.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: Windows

Control ID: 5af39596ea7d41fe7e61f8201685f7f0ee470c7b1e19fbce05cf0140f8ae2526