APPL-14-003009 - The macOS system must prohibit password reuse for a minimum of five generations.

Information

The macOS must be configured to enforce a password history of at least five previous passwords when a password is created.

This rule ensures that users are not allowed to reuse a password that was used in any of the five previous password generations.

Limiting password reuse protects against malicious users attempting to gain access to the system via brute-force hacking methods.

Note: The guidance for password-based authentication in NIST 800-53 (Rev 5) and NIST 800-63B state that complexity rules should be organizationally defined. The values defined are based on common complexity values, but an organization may define its own password complexity rules.

Solution

Configure the macOS system to prohibit password reuse for five generations by installing the "com.apple.mobiledevice.passwordpolicy" configuration profile.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_14_V1R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(e), CAT|II, CCI|CCI-000200, Rule-ID|SV-259539r941239_rule, STIG-ID|APPL-14-003009, Vuln-ID|V-259539

Plugin: Unix

Control ID: 5bc8822b4d450c18953ba28064f58e33d787ccd2259acabce46a3520dc152a7e