WN08-00-000009 - Administrator passwords must be changed as required.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the passwords. Passwords for the default and emergency administrator accounts must be changed at least annually or when any member of the administrative team leaves the organization.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define a policy that requires the default and emergency administrator passwords to be changed at least annually or when any member of the administrative team leaves the organization. Ensure the policy is implemented.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_8_and_8-1_V1R23_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-48166r1_rule, STIG-ID|WN08-00-000009, Vuln-ID|V-14225

Plugin: Windows

Control ID: 3a6d7ed9777d21df33838e83242e5d94b64974d44028ba40dd95feb37ebd7e23