Catalina - Prevent the Use of Dictionary Words for Passwords

Information

The macOS should be configured to forbid users to use dictionary words for passwords.

If the operating system allows users to select passwords based on dictionary words, this increases the window of opportunity for a malicious user to guess the password.

To prevent users from using dictionary words for passwords, many operating systems can be integrated with an enterprise-level directory service that meets or exceeds this requirement.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented, but this finding cannot be considered fixed.

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CCE|CCE-84910-9, CCI|CCI-000366

Plugin: Unix

Control ID: c40fd79eef4e4696405c1dab738a92d4597873159230c59a2861dca1cb96d2bb