4.018 - Application account passwords length and change requirement

Information

Setting application accounts to expire may cause applications to stop functioning. The site will have a policy that application account passwords manually generated and entered by a system administrator are changed at least annually or when a system administrator with knowledge of the password leaves the organization. Application/service account passwords will be at least 15 characters and follow complexity requirements for all passwords.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Create application/service account passwords that are at least 15 characters in length and meet complexity requirements. Change application/service account passwords that are manually generated and entered by a system administrator at least annually or whenever an administrator with knowledge of the password leaves the organization.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-2(10), 800-53|IA-5(1)(a), CAT|II, CCI|CCI-000205, CCI|CCI-002142, Rule-ID|SV-29336r1_rule, STIG-ID|4.018, Vuln-ID|V-14271

Plugin: Windows

Control ID: 4e4814714893d40a45bf0d8b549cdd53d1820ced59684427357ebfa65d3493ff