Information
The macOS should be configured to forbid users to use dictionary words for passwords.
If the operating system allows users to select passwords based on dictionary words, this increases the window of opportunity for a malicious user to guess the password.
To prevent users from using dictionary words for passwords, many operating systems can be integrated with an enterprise-level directory service that meets or exceeds this requirement.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented, but this finding cannot be considered fixed.