WN08-00-000009 - Administrator passwords must be changed as required.

Information

The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the passwords. Passwords for the default and emergency administrator accounts must be changed at least annually or when any member of the administrative team leaves the organization.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define a policy that requires the default and emergency administrator passwords to be changed at least annually or when any member of the administrative team leaves the organization. Ensure the policy is implemented.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_8_and_8-1_V1R23_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-48166r1_rule, STIG-ID|WN08-00-000009, Vuln-ID|V-14225

Plugin: Windows

Control ID: 3a6d7ed9777d21df33838e83242e5d94b64974d44028ba40dd95feb37ebd7e23